Техническая информация
- '%APPDATA%\start.exe'
- '%APPDATA%\Install.exe'
- '<SYSTEM32>\rundll32.exe' shell32.dll,Control_RunDLL "%APPDATA%\Skype.cpl",
- '<SYSTEM32>\cmd.exe' /c ""%APPDATA%\Open2.bat" "
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\st[1].img
- %TEMP%\DefaultPackOffer.dll
- <LS_APPDATA>\tmp.zip
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\teste[1].zip
- %APPDATA%\start.exe
- %APPDATA%\Skype.cpl
- %APPDATA%\Open2.bat
- %APPDATA%\Install.exe
- %TEMP%\DefaultPackOffer.dll
- 'www.em##o.pl':80
- '16#.#09.51.218':80
- www.em##o.pl/templates/atomic/language/en-GB/teste.zip
- 16#.#09.51.218/2013/st.img
- DNS ASK www.em##o.pl
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'