Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'lbs' = '%PROGRAM_FILES%\lbs\lbs.exe'
- %PROGRAM_FILES%\lbs\lbs.exe
- %PROGRAM_FILES%\lbs\lbs.exe (загружен из сети Интернет)
- %PROGRAM_FILES%\lbs\lbs.dll
- %PROGRAM_FILES%\lbs\lbs.exe
- 'www.ye##.co.kr':80
- www.ye##.co.kr/setupLBS1/lbs.dll
- www.ye##.co.kr/setupLBS1/lbs.exe.MZ?
- www.ye##.co.kr/php/vrs_lbs1/vrs.php
- DNS ASK www.ye##.co.kr
- ClassName: 'Shell_TrayWnd' WindowName: ''