Техническая информация
- [<HKLM>\SOFTWARE\Classes\iexplorexFile\shell\open\command] '' = ''
- 'C:\rising.exe'
- '<SYSTEM32>\wscript.exe' C:\\Killme.vbs
- '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE' http://www.51##688.com/?t
- '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE' http://www.77##7.com/setup.asp?ga##
- C:\Killme.vbs
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\setup[1].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\5136688[1]
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\launch internet explorer browser.iexplorex
- %TEMP%\aut1.tmp
- C:\rising.exe
- %TEMP%\aut2.tmp
- C:\rising.exe
- C:\Killme.vbs
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\setup[1].asp
- %TEMP%\aut1.tmp
- %TEMP%\aut2.tmp
- 'localhost':1039
- 'www.51##688.com':80
- 'localhost':1036
- 'www.77##7.com':80
- www.51##688.com/?t
- www.77##7.com/setup.asp?ga##
- DNS ASK www.51##688.com
- DNS ASK www.77##7.com
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: '' WindowName: '(null)'