Техническая информация
- <SYSTEM32>\mshta.exe ""%TEMP%\up.hta""
- <SYSTEM32>\wscript.exe ""%TEMP%\alltop.vbs""
- <SYSTEM32>\wscript.exe ""%TEMP%\mytop.vbs""
- %TEMP%\up.hta
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\s1x2f58f6[1].gif
- %TEMP%\alltop.vbs
- %ALLUSERSPROFILE%\Desktop\Internet Explroer.url
- %TEMP%\mytop.vbs
- %TEMP%\up.hta
- %TEMP%\alltop.vbs
- %TEMP%\mytop.vbs
- 'up.#l0.net':80
- 'localhost':1037
- up.#l0.net/taup/s1x2f58f6.gif
- DNS ASK up.#l0.net
- ClassName: 'Shell_TrayWnd' WindowName: ''