Техническая информация
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -nohome
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\selfdel0.bat" "
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' http://bi#.ly/2nfps4Z
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\batfile.bat" "
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' http://bi#.ly/2p6qHqq
- %TEMP%\1.tmp\batfile.bat
- %TEMP%\1.tmp\batfile.bat
- 'bi#.ly':80
- 'tu#######s-espanol.blogspot.com':80
- 'localhost':1040
- 'localhost':1038
- 'localhost':1039
- http://tu#######s-espanol.blogspot.com/
- http://bi#.ly/2p6qHqq
- http://bi#.ly/2nfps4Z
- DNS ASK tu#######s-espanol.blogspot.com
- DNS ASK bi#.ly
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''