Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\microsoft.exe
- %HOMEPATH%\Start Menu\Programs\Startup\microsoft.exe
- %WINDIR%\system.exe (загружен из сети Интернет)
- %TEMP%\aut1.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\system[1].exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\system[1].exe
- %WINDIR%\system.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\system[1].exe
- %TEMP%\aut1.tmp
- 'h1.##pway.com':80
- h1.##pway.com/arab32/system.exe
- DNS ASK h1.##pway.com