Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'nc_id' = '<SYSTEM32>\MSRec.EXE'
- <SYSTEM32>\MSREC.EXE
- <SYSTEM32>\Rec.exe
- <SYSTEM32>\Rec.exe
- <SYSTEM32>\MSREC.EXE
- <SYSTEM32>\mydir1.dll
- <SYSTEM32>\Epsonp.{992CFFA0-F557-101A-88EC-00DD010CCC48}\me.dat
- 'zw##.##inacattle.net':80
- zw##.##inacattle.net/zs6mc8a/jjssqq/cf.asp?c=#####
- DNS ASK zw##.##inacattle.net
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: '#32770' WindowName: ''
- ClassName: '' WindowName: '????(S)'
- ClassName: '' WindowName: 'dede'
- ClassName: '' WindowName: 'DarK 3.50.04 (c) 1999-2003 by DaFixer/TMG'
- ClassName: 'Shell_TrayWnd' WindowName: ''