Техническая информация
- '%TEMP%\crgg.exe' tiseno.looporillo.com skachat-igru-pdd-vozhdenie-besplatno.zip
- '%TEMP%\ext.exe'
- '%TEMP%\stpf.exe' df89a8b1c2a1bab86959206f5422eaf7 tiseno.looporillo.com /images/srvr/partner/send.php 5
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\crgg.exe.bat" crgg.exe tiseno.looporillo.com skachat-igru-pdd-vozhdenie-besplatno.zip"
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\ext.exe.bat" ext.exe "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\stpf.exe.bat" stpf.exe df89a8b1c2a1bab86959206f5422eaf7 tiseno.looporillo.com /images/srvr/partner/send.php 5"
- %PROGRAM_FILES%\Compan\OldProd\dancedance.txt
- %PROGRAM_FILES%\Compan\OldProd\lopera.txt
- %PROGRAM_FILES%\Compan\OldProd\pozvoni.vbs
- %PROGRAM_FILES%\Compan\OldProd\alene.vbs
- %PROGRAM_FILES%\Compan\OldProd\Uninstall.exe
- %PROGRAM_FILES%\Compan\OldProd\Uninstall.ini
- %PROGRAM_FILES%\Compan\OldProd\midiiiia.bat
- %PROGRAM_FILES%\Compan\OldProd\lidogeneratsiya.bat
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\stpf.exe
- %TEMP%\ext.exe
- <Текущая директория>\s
- <Текущая директория>\c
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\send[1].htm
- %TEMP%\$inst\2.tmp
- %TEMP%\crgg.exe
- %TEMP%\f29dbf62d7254ba08bc2e29426a89564
- %TEMP%\stpf.exe
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\2.tmp
- <Текущая директория>\c
- <Текущая директория>\s
- %TEMP%\f29dbf62d7254ba08bc2e29426a89564
- 'ti####.looporillo.com':80
- DNS ASK ti####.looporillo.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'