Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'run' = '%WINDIR%\iedwf.exe'
- %WINDIR%\iedwf.exe
- %WINDIR%\regedit.exe
- ClassName: 'DRAGONNEST' WindowName: '??????'
- %TEMP%\1c791.tmp
- %TEMP%\fuc4.tmp
- %TEMP%\1cd1f.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\52pjwg[1]
- %TEMP%\1d1a5.tmp
- %TEMP%\Temp\Systemp.exe
- %TEMP%\Temp\0901УЕЦ®А¶.exe
- %TEMP%\fuc1.tmp
- %TEMP%\fuc3.tmp
- %TEMP%\fuc2.tmp
- %TEMP%\1cd1f.tmp
- %TEMP%\1d1a5.tmp
- %TEMP%\Temp\Systemp.exe
- %TEMP%\1c791.tmp
- 'www.52##wg.com':80
- 'localhost':1036
- www.52##wg.com/
- DNS ASK www.52##wg.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''