Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows Script Host' = 'winhost32.exe'
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\s4[1].130&id=Socks4%20RC3&win=USER-4BB09A9C02-%USERNAME%&rpass=WinXP&connection=LAN&s7pass=55555
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\s4[1].130&id=Socks4%20RC3&win=USER-4BB09A9C02-%USERNAME%&rpass=WinXP&connection=LAN&s7pass=55555
- 'pu####.k0nsl.net':80
- 'localhost':1037
- pu####.k0nsl.net/cgi-bin/socks4/s4.cgi?ac###############################################################################################################################
- DNS ASK pu####.k0nsl.net