Техническая информация
- 'C:\coleot.exe'
- '<SYSTEM32>\rundll32.exe' shell32.dll,Control_RunDLL "C:\textado.cpl",
- '<SYSTEM32>\cmd.exe' /c ""C:\goram.bat" "
- <LS_APPDATA>\temp.zip
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\extensor[1].zip
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\pjp[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\pjp[1]
- C:\textado.cpl
- C:\goram.bat
- C:\coleot.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\pjp[1]
- 'we##ai|.him':80
- 'localhost':1038
- 'www.co#####webbvg.com.br':80
- we##ai|.him/bjnpbp*aouoby/pjp
- www.co#####webbvg.com.br/02-09BL/extensor.zip
- DNS ASK we##ai|.him
- DNS ASK www.co#####webbvg.com.br
- ClassName: 'MS_WINHELP' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'