Техническая информация
- Диспетчера задач (Taskmgr)
- Редактора реестра (RegEdit)
- Компонент восстановления системы (SR)
- '%WINDIR%\regedit.exe' /s %WINDIR%\twain.reg
- <SYSTEM32>\cmd.exe
- ntvdm.exe
- ecmd.exe
- firefox.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\swvq9mk5[1].png
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\clual8ckdwdx[1].png
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\60065l[1].gif
- %WINDIR%\twain.reg
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\url[1].php
- <DRIVERS>\etc\hosts
- 'www.tr####ounter.com':80
- 'wh###ead.com':80
- 'wh##.amung.us':80
- 'localhost':1036
- 'tu###eru.net':80
- www.tr####ounter.com/w/blog/ff0000_ffffff/swvq9mk5.png
- wh###ead.com/counter/60065l.gif
- tu###eru.net/url.php
- wh##.amung.us/swidget/clual8ckdwdx.png
- DNS ASK www.tr####ounter.com
- DNS ASK wh###ead.com
- DNS ASK tu###eru.net
- DNS ASK wh##.amung.us
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'RegEdit_RegEdit' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'