Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\QQVE.sys] 'Start' = '00000002'
- <DRIVERS>\QQVE.sys
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\4[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\3[1].htm
- %TEMP%\1b4a5.tmp
- %TEMP%\1c000.tmp
- %TEMP%\1c996.tmp
- %TEMP%\1c996.tmp
- <DRIVERS>\QQVE.sys
- %TEMP%\1b4a5.tmp
- %TEMP%\1c000.tmp
- 'www.78##a.com':80
- 'ww##.78gua.com':80
- 'localhost':1035
- www.78##a.com/3.htm
- www.78##a.com/tyf.txt
- ww##.78gua.com/4.htm
- DNS ASK www.78##a.com
- DNS ASK ww##.78gua.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''