Техническая информация
- '<SYSTEM32>\wscript.exe' "%TEMP%\1.tmp\2.vbs"
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -nohome
- '%APPDATA%\Rar$326373Hsft\Hack.exe'
- '%APPDATA%\Rar$326373Hsft\Activator.exe'
- ClassName: 'OLLYDBG', WindowName: ''
- %TEMP%\1.tmp\2.vbs
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\hells-hack[1]
- %APPDATA%\Rar$326373Hsft\Activator.exe
- %APPDATA%\Rar$326373Hsft\Hack.exe
- %TEMP%\1.tmp\2.vbs
- 'my#####orlic.ucoz.ru':80
- 'www.yo##ube.com':443
- 'localhost':1039
- 'localhost':1036
- 'he###-hack.com':80
- http://my#####orlic.ucoz.ru/WormixCheat.ver
- http://he###-hack.com/
- DNS ASK www.yo##ube.com
- DNS ASK my#####orlic.ucoz.ru
- DNS ASK he###-hack.com
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''