Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'cohost' = 'c:\drivers\hstart.exe /NOCONSOLE /D="c:\drivers\" "c:\drivers\oshost.exe"'
- C:\drivers\addd.zip
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\get_zip[1].php
- 'ha##ls.com':80
- 'localhost':1036
- ha##ls.com/exe/get_zip.php?id#######
- DNS ASK ha##ls.com
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'