Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\6to4] 'Start' = '00000002'
- '<SYSTEM32>\cmd.exe' /c ""%WINDIR%\temp\temp0.bat" "
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\K8CFG5EL\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\7Z912L4E\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\YMFVT128\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\6VO5KJ43\desktop.ini
- %WINDIR%\Installer\AMDEx.msi
- %WINDIR%\Temp\temp0.bat
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\7Z912L4E\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\YMFVT128\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\6VO5KJ43\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\K8CFG5EL\desktop.ini
- 'www.wl###wupdate.us':81
- DNS ASK www.wl###wupdate.us