Техническая информация
- %TEMP%\ext.exe
- %TEMP%\fsetup.exe 35f4a8d465e6e1edc05f3d8ab658c551 www.ar###english.de
- %TEMP%\install_flashplayer11.exe "<Полный путь к вирусу>" 2908
- <SYSTEM32>\cmd.exe /c ""%PROGRAM_FILES%\jobs\jobs\dima_bilan.bat" "
- <SYSTEM32>\wscript.exe "%PROGRAM_FILES%\jobs\jobs\edet.vbs"
- <SYSTEM32>\cmd.exe /c ""%TEMP%\fsetup.exe.bat" fsetup.exe 35f4a8d465e6e1edc05f3d8ab658c551 www.ar####nglish.de"
- <SYSTEM32>\cmd.exe /c ""%TEMP%\ext.exe.bat" ext.exe "
- %PROGRAM_FILES%\jobs\jobs\edet.vbs
- %PROGRAM_FILES%\jobs\jobs\dima_bilan.bat
- %PROGRAM_FILES%\jobs\jobs\ruoshka.txt
- %HOMEPATH%\Recent\jobs.lnk
- %HOMEPATH%\Recent\edet.lnk
- %PROGRAM_FILES%\jobs\jobs\v_habarovks.vbs
- %PROGRAM_FILES%\jobs\jobs\mainlol.txt
- %TEMP%\ext.exe
- %TEMP%\fsetup.exe
- %TEMP%\install_flashplayer11.exe
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\2.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\download_dll[1].htm
- %TEMP%\$inst\2.tmp
- %TEMP%\ext.exe
- %TEMP%\fsetup.exe
- %TEMP%\$inst\temp_0.tmp
- '94.##9.188.143':9007
- 'localhost':1038
- 'www.ar###english.de':80
- DNS ASK www.ar###english.de
- ClassName: 'Shell_TrayWnd' WindowName: ''