Техническая информация
- '<SYSTEM32>\ftp.exe' /C echo get >>g5.dat
- '<SYSTEM32>\ftp.exe' /pid=3404
- '<SYSTEM32>\ftp.exe' -s:g6.dat
- '<SYSTEM32>\ftp.exe' -s:g3.dat
- '<SYSTEM32>\ftp.exe' -s:g.dat
- '<SYSTEM32>\ftp.exe' -s:g1.dat
- '<SYSTEM32>\ftp.exe' -s:g2.dat
- <SYSTEM32>\ftp.exe
- <SYSTEM32>\cmd.exe
- %TEMP%\g3.dat
- %TEMP%\g3.bat
- %TEMP%\g4.dat
- %TEMP%\g1.bat
- %TEMP%\g2.dat
- %TEMP%\g2.bat
- %TEMP%\g4.bat
- %TEMP%\g6.bat
- %TEMP%\g7.dat
- %TEMP%\g7.bat
- %TEMP%\g5.dat
- %TEMP%\g5.bat
- %TEMP%\g6.dat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\iplookup[1].php
- %TEMP%\i.rar
- %TEMP%\nsj3.tmp\System.dll
- %TEMP%\nso2.tmp
- %TEMP%\nsj3.tmp\Base64.dll
- %TEMP%\nsj3.tmp\Inetc.dll
- %PROGRAM_FILES%\StpOnline\Unload.exe
- %TEMP%\g.dat
- %TEMP%\g.bat
- %TEMP%\g1.dat
- %HOMEPATH%\Start Menu\Programs\StpOnline\Unload.lnk
- %TEMP%\nsj3.tmp\nsProcess.dll
- %TEMP%\nsj3.tmp\ExecCmd.dll
- %TEMP%\g4.dat
- %TEMP%\g5.dat
- %TEMP%\g6.dat
- %TEMP%\g1.dat
- %TEMP%\g2.dat
- %TEMP%\g3.dat
- 'localhost':1045
- 'localhost':1043
- 'localhost':1049
- 'localhost':1047
- 'localhost':1041
- 'localhost':1037
- 'in#.###ol.sina.com.cn':80
- 'localhost':1039
- 'www.mu####hiyanji.com':21
- in#.###ol.sina.com.cn/iplookup/iplookup.php
- DNS ASK www.mu####hiyanji.com
- DNS ASK in#.###ol.sina.com.cn
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'