Техническая информация
- '%TEMP%\dxkroee.exe'
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n
- '<SYSTEM32>\taskkill.exe' /f /im dxkroee.exe
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 3
- '<SYSTEM32>\cmd.exe' /c call dxkroeeZS.bat
- %TEMP%\dxkroee.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\qlogin_div[1].html
- <SYSTEM32>\hide.sys
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\config[1].xml
- <Текущая директория>\dxkroeeZS.bat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\r[1].asp
- %TEMP%\hidep.dll
- %TEMP%\bfwjunh
- %TEMP%\aut1.tmp
- %TEMP%\aut2.tmp
- %TEMP%\aut3.tmp
- %TEMP%\dxkroee.exe
- %TEMP%\aut3.tmp
- <SYSTEM32>\hide.sys
- %TEMP%\hidep.dll
- %TEMP%\aut1.tmp
- %TEMP%\bfwjunh
- %TEMP%\aut2.tmp
- 'www.63##6.com':80
- 'xu#.##login2.qq.com':80
- 'localhost':1036
- www.63##6.com/r.asp?fr######################
- xu#.##login2.qq.com/div/qlogin_div.html?u1##################
- www.63##6.com/App/weixin/config/config.xml
- DNS ASK www.63##6.com
- DNS ASK xu#.##login2.qq.com
- ClassName: '(null)' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'