Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Ms Win Process Services' = '"%WINDIR%\shost.exe"'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Ms Windows32 Process Host Service' = '"%WINDIR%\system\fservices.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Ms Win Process Services' = '"%WINDIR%\shost.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Ms Windows32 Process Host Service' = '"%WINDIR%\system\fservices.exe"'
- <Текущая директория>\windowmicrosoft.sys
- %TEMP%\~DFAC28.tmp
- '67.##5.160.76':5001
- DNS ASK vc#.##.#ip.dcn.yahoo.com
- ClassName: 'Indicator' WindowName: ''