Техническая информация
- C:\KINSTALLERS_66_4158.exe
- C:\haoie3538.exe
- C:\KINSTALLERS_66_4158.exe (загружен из сети Интернет)
- C:\haoie3538.exe (загружен из сети Интернет)
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\jump[1].php
- C:\KINSTALLERS_66_4158.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\haoie3538[1].exe
- C:\haoie3538.exe
- 'j.#####.ijinshan.com':80
- 'd.#####.ijinshan.com':80
- 'localhost':1035
- j.#####.ijinshan.com/jump.php?u_########
- d.#####.ijinshan.com/haoie/link/haoie3538.exe
- DNS ASK j.#####.ijinshan.com
- DNS ASK d.#####.ijinshan.com