Техническая информация
- '<SYSTEM32>\cmd.exe' /C del /Q /F "%TEMP%\sys1.tmp"
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\shimgvw.dll,ImageView_Fullscreen %HOMEPATH%\Desktop\ykcol.bmp
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -nohome
- <STUBS_DIR>\GVOnline\ykcol-602c.htm
- <STUBS_DIR>\l2\RYIIIX1U-6ATE-DCGB-73A7E5BE-40ED2A855781.ykcol
- C:\RYIIIX1U-6ATE-DCGB-687C5C8B-BD1B729994ED.ykcol
- <STUBS_DIR>\GVOnline\RYIIIX1U-6ATE-DCGB-1D62DB5C-B75AC508B52F.ykcol
- <STUBS_DIR>\l2\ykcol-357a.htm
- %HOMEPATH%\Desktop\ykcol.htm
- %HOMEPATH%\Desktop\ykcol.bmp
- <STUBS_DIR>\lin\RYIIIX1U-6ATE-DCGB-24460CB5-71AC85765F54.ykcol
- <STUBS_DIR>\lin\ykcol-c0d6.htm
- C:\Documents and Settings\LocalService\Local Settings\<INETFILES>\Content.IE5\RYIIIX1U-6ATE-DCGB-FF1B6CE0-FF817C4487E8.ykcol
- C:\Far2\ykcol-1f4e.htm
- C:\ykcol-c3f6.htm
- C:\Documents and Settings\Default User\Templates\ykcol-e811.htm
- %HOMEPATH%\Templates\ykcol-324d.htm
- <STUBS_DIR>\ykcol-01f1.htm
- C:\Documents and Settings\LocalService\Cookies\RYIIIX1U-6ATE-DCGB-B9D79000-57FEC5231635.ykcol
- C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\RYIIIX1U-6ATE-DCGB-B3AE5EDA-89C302A25153.ykcol
- C:\Far2\Addons\ykcol-e9dd.htm
- C:\Documents and Settings\Default User\ykcol-632d.htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\GDUJMLMB\desktop.ini
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\NBRWB1DY\desktop.ini
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\O12CVNXG\desktop.ini
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\EKGER7TL\desktop.ini
- из <Полный путь к файлу> в %TEMP%\sys1.tmp
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'ShImgVw:CPreviewWnd' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''