Техническая информация
- %WINDIR%\Tasks\USA.bat
- [<HKLM>\SYSTEM\ControlSet001\Services\BITS] 'Start' = '00000002'
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\54ECYZCR\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\85MFSDU3\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\NQMYKTMJ\desktop.ini
- %TEMP%\114968_res.tmp
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\RNAFOZA9\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\54ECYZCR\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\85MFSDU3\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\NQMYKTMJ\desktop.ini
- <SYSTEM32>\RcmhtgC.dll
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\RNAFOZA9\desktop.ini
- 'www.ha##er.com':80
- www.ha##er.com/ip.txt
- DNS ASK wpad.localdomain
- DNS ASK www.ha##er.com