Техническая информация
- %TEMP%\e.exe -s
- %TEMP%\gfvmv.sys
- %TEMP%\e.exe
- <SYSTEM32>\wbem\Performance\WmiApRpl_new.ini
- 'hi.##idu.com':80
- hi.##idu.com/qifanwuyou/blog/item/535b0ddb9b64f5c5562c84e9.html
- DNS ASK hi.##idu.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'SANGUO' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''