Техническая информация
- %WINDIR%\Temp\20118512646.exe
- %WINDIR%\Temp\20118512645.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\1be20b152a2acb5f42a9ada9[1].html
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\05773f12951ffe185baf532c[1].html
- <SYSTEM32>\GroupPolicy\User\Scripts\script.ini
- %WINDIR%\Temp\20118512645.exe
- %WINDIR%\Temp\20118512646.exe
- 'hi.##idu.com':80
- '57####650.3322.org':1604
- hi.##idu.com/stevety/blog/item/05773f12951ffe185baf532c.html
- hi.##idu.com/x5et123/blog/item/1be20b152a2acb5f42a9ada9.html
- DNS ASK hi.##idu.com
- DNS ASK 57####650.3322.org
- '<IP-адрес в локальной сети>':1034
- ClassName: 'Shell_TrayWnd' WindowName: ''