Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\6to4] 'Start' = '00000002'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\TempDel.bat" "
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\SLQJGXUV\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\NZU32DDN\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\VPUPVKFQ\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\NZU32DDN\31[1].txt
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\OTMP6VKN\desktop.ini
- %TEMP%\TempFile.Log
- %TEMP%\TempAdv.dll
- <SYSTEM32>\ShowIP.dll
- %TEMP%\TempDel.bat
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\VPUPVKFQ\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\OTMP6VKN\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\NZU32DDN\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\SLQJGXUV\desktop.ini
- %TEMP%\TempAdv.dll
- %TEMP%\TempFile.sys
- %TEMP%\TempFile.Log в %TEMP%\TempFile.sys
- 'www.ip###ugou.com':80
- 'localhost':1037
- www.ip###ugou.com/bbs/txt/31.txt
- DNS ASK www.ip###ugou.com