Техническая информация
- '<SYSTEM32>\regsvr32.exe' /s "%TEMP%\~DFA3783.tmp"
- '<SYSTEM32>\regsvr32.exe' /s "<SYSTEM32>\mswinsck.ocx"
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\file[1].txt
- %TEMP%\~DFA9A3C.TMP
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\file[1].txt
- %TEMP%\DFA5072.tmp
- %WINDIR%\sys.dat
- %TEMP%\~DFA3783.tmp
- <SYSTEM32>\mswinsck.ocx
- %TEMP%\DFA5072.tmp
- 'www.ys##.net':80
- 'www.pc##8.net':80
- 'localhost':1035
- www.ys##.net/file.txt
- www.pc##8.net/file.txt
- DNS ASK www.v1##.net
- DNS ASK www.ys##.net
- DNS ASK www.pc##8.net