Техническая информация
- %WINDIR%\2.bat
- %WINDIR%\Temp\temp\Thanks.exe
- %WINDIR%\2.bat (загружен из сети Интернет)
- <SYSTEM32>\rundll32.exe <SYSTEM32>\shimgvw.dll,ImageView_Fullscreen %WINDIR%\temp\temp\jessi.jpg
- %WINDIR%\1.rar
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\b[1].rar
- %WINDIR%\2.bat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\a[1].bat
- %WINDIR%\Temp\temp\Thanks.exe
- %WINDIR%\Temp\temp\jessi.jpg
- %HOMEPATH%\Recent\temp.lnk
- %HOMEPATH%\Recent\jessi.lnk
- 'www.go###e.ekiwi.es':80
- 'localhost':1035
- www.go###e.ekiwi.es/qtmiro/a.bat
- www.go###e.ekiwi.es/qtmiro/b.rar
- DNS ASK www.go###e.ekiwi.es
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'ShImgVw:CPreviewWnd' WindowName: ''