Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\UPHClean] 'Start' = '00000002'
- '%PROGRAM_FILES%\UPHClean\uphclean.exe'
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\RAV2007.BAT
- ClassName: '(null)' WindowName: 'TRW2000 for Windows 9x'
- ClassName: '(null)' WindowName: 'API-Log v1.2 by M.o.D. [F2F]'
- ClassName: 'OLLYDBG' WindowName: '(null)'
- C:\Documents and Settings\LocalService\Favorites\Desktop.ini
- %WINDIR%\RAV2007.BAT
- %PROGRAM_FILES%\UPHClean\uphclean.exe
- %PROGRAM_FILES%\UPHClean\uphclean.dll
- C:\Documents and Settings\LocalService\Favorites\Desktop.ini
- %PROGRAM_FILES%\UPHClean\uphclean.dll
- %PROGRAM_FILES%\UPHClean\uphclean.exe
- 'je####ity.vicp.net':4037
- DNS ASK je####ity.vicp.net
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: '(null)' WindowName: 'Hacked Spy'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: '(null)' WindowName: 'The Customiser'
- ClassName: 'VxDMonClass' WindowName: '(null)'
- ClassName: '(null)' WindowName: 'TrainerSpy XP + NT / 2000 / XP + Coded By BofeN'
- ClassName: '(null)' WindowName: 'The Customiser Configuration Screen'
- ClassName: '(null)' WindowName: 'Cool Debugger for Win32'