Техническая информация
- C:\FunshionInstall.exe (загружен из сети Интернет)
- %PROGRAM_FILES%\Project.exe
- <SYSTEM32>\reg.exe add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Default_Page_URL" /t reg_sz /d http://www.q7##2.com /f
- <SYSTEM32>\reg.exe add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /t reg_sz /d http://www.q7##2.com /f
- <SYSTEM32>\cmd.exe /c ""%PROGRAM_FILES%\2345.bat" "
- %WINDIR%\1312611395_6634280_1284967193_20.fsp
- C:\FunshionInstall.exe
- %PROGRAM_FILES%\Project.exe
- %PROGRAM_FILES%\2345.bat
- 'ne#####.funshion.com':80
- ne#####.funshion.com/download/silent/108988/FunshionInstall.exe
- DNS ASK ne#####.funshion.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''