Техническая информация
- '%TEMP%\NexonRepair.exe'
- '<SYSTEM32>\dwahrvna.exe'
- 'C:\uu.exe'
- '%TEMP%\0wF1TQ01S9.exe'
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\attrib.exe' "%TEMP%\0wF1TQ01S9.exe" -h -r -s
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\j1s24rywqycr8am.bat"
- <SYSTEM32>\dwahrvna.exe
- <SYSTEM32>\dwahrvna.exe
- <SYSTEM32>\MSWINSCK.ocx
- %TEMP%\NexonRepairList.txt
- %TEMP%\j1s24rywqycr8am.bat
- %TEMP%\NexonRepair.exe
- C:\path.dll
- C:\uu.exe
- %TEMP%\0wF1TQ01S9.exe
- <SYSTEM32>\dwahrvna.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\MSWINSCK[1].OCX
- %TEMP%\0wF1TQ01S9.exe
- %TEMP%\~DF6AF3.tmp
- %TEMP%\~DFAE8D.tmp
- '11#.#57.117.17':5882
- 'bl##.naver.com':80
- 'localhost':1039
- 'localhost':1036
- 'pd###.egloos.com':80
- bl##.naver.com/PostView.nhn?bl####################################
- pd###.egloos.com/pds/201401/25/40/MSWINSCK.OCX
- DNS ASK bl##.naver.com
- DNS ASK pd###.egloos.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'SysListView32' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''