Техническая информация
- %TEMP%\V2011\svchost.exe
- %WINDIR%\Temp\20128191817.exe
- <SYSTEM32>\cmd.exe /c afc9fe2f418b00a0.bat
- <SYSTEM32>\rundll32.exe <SYSTEM32>\shimgvw.dll,ImageView_Fullscreen %WINDIR%\temp\20128191815.jpg
- %HOMEPATH%\Recent\20128191815.lnk
- %HOMEPATH%\Recent\Temp.lnk
- %WINDIR%\Temp\afc9fe2f418b00a0.bat
- %WINDIR%\Temp\20128191815.jpg
- %WINDIR%\Temp\20128191817.exe
- %TEMP%\V2011\svchost.exe
- %WINDIR%\Temp\20128191817.exe
- 'hu#####angyong.3322.org':2011
- DNS ASK hu#####angyong.3322.org
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'ShImgVw:CPreviewWnd' WindowName: ''