Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\GooglServics.lnk
- %HOMEPATH%\Start Menu\Programs\Startup\HddDirve.lnk
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\HddDirve.lnk
- %HOMEPATH%\winsvcr.exe
- %HOMEPATH%\wincert.exe
- <SYSTEM32>\xcopy.exe "%TEMP%\HddDirve.lnk" "%HOMEPATH%\Start Menu\Programs\Startup" /Y
- <SYSTEM32>\ipconfig.exe /all
- <SYSTEM32>\wscript.exe "%HOMEPATH%\R.vbs"
- <SYSTEM32>\wscript.exe "%HOMEPATH%\wins.vbs"
- <SYSTEM32>\rundll32.exe <SYSTEM32>\shell32.dll,OpenAs_RunDLL %HOMEPATH%\scan.docx
- <SYSTEM32>\xcopy.exe "%TEMP%\HddDirve.lnk" "%ALLUSERSPROFILE%\Start Menu\Programs\Startup" /Y
- %HOMEPATH%\R.vbs
- %TEMP%\iconfall.log
- %HOMEPATH%\GooglServics.lnk
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\snwd[1].php
- %APPDATA%\NTUSER\mxole.cpx
- %HOMEPATH%\winsvcr.exe
- %HOMEPATH%\wins.vbs
- %HOMEPATH%\scan.docx
- %TEMP%\HddDirve.lnk
- %HOMEPATH%\wincert.exe
- 'sk###rzone.org':80
- 'localhost':1035
- sk###rzone.org/draw/snwd.php?tp################################################################################################################
- DNS ASK sk###rzone.org
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''