Техническая информация
- '%TEMP%\RarSFX0\waigua.exe' start
- '%TEMP%\RarSFX0\gengxin.exe' start
- '<SYSTEM32>\wscript.exe' "%TEMP%\RarSFX0\Miner.vbs"
- %TEMP%\RarSFX0\gengxin.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\520aion[1].htm
- %TEMP%\RarSFX0\Miner.vbs
- %TEMP%\RarSFX0\waigua.exe
- %TEMP%\RarSFX0\gengxin.exe
- %TEMP%\RarSFX0\gengxin.exe
- 'www.17##gz.com':80
- 'localhost':1036
- www.17##gz.com/tj/520aion.htm
- DNS ASK www.17##gz.com
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'msctls_updown32' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'