Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\QQVE.sys] 'Start' = '00000002'
- <DRIVERS>\QQVE.sys
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\4[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\3[1].htm
- %TEMP%\1d04b.tmp
- %TEMP%\1d628.tmp
- %TEMP%\1dbc6.tmp
- %TEMP%\1dbc6.tmp
- <DRIVERS>\QQVE.sys
- %TEMP%\1d04b.tmp
- %TEMP%\1d628.tmp
- 'www.78##a.com':80
- 'ww##.78gua.com':80
- 'localhost':1038
- www.78##a.com/tyf.txt
- ww##.78gua.com/3.htm
- ww##.78gua.com/4.htm
- DNS ASK www.78##a.com
- DNS ASK ww##.78gua.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''