Техническая информация
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\lsass.exe
- <SYSTEM32>\csrss.exe
- <SYSTEM32>\spoolsv.exe
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\09M3C5EV\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\UL8RIPCN\gate[1].php
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\UL8RIPCN\wpad[1].dat
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\9PU6EJRT\desktop.ini
- %TEMP%\7af3996f
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\UL8RIPCN\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\SLE3CLMN\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\9PU6EJRT\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\09M3C5EV\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\UL8RIPCN\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\SLE3CLMN\desktop.ini
- %TEMP%\7af3996f
- 'wpad.localdomain':80
- '<IP-адрес в локальной сети>':80
- wpad.localdomain/wpad.dat
- <IP-адрес в локальной сети>/btn6/gate.php?dw####
- <IP-адрес в локальной сети>/btn6/gate.php?in######################################
- DNS ASK wpad.localdomain