Техническая информация
- '<SYSTEM32>\cmd.exe' /C del /Q /F "%TEMP%\sys1.tmp"
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\shimgvw.dll,ImageView_Fullscreen %HOMEPATH%\Desktop\lukitus.bmp
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -nohome
- <STUBS_DIR>\GVOnline\lukitus-ee84.htm
- <STUBS_DIR>\l2\RYIIIXUY-6ATE-NGDY-F504CEBF-1A06EB20D355.lukitus
- C:\RYIIIXUY-6ATE-NGDY-E168F997-802B8572CFFB.lukitus
- <STUBS_DIR>\GVOnline\RYIIIXUY-6ATE-NGDY-726DAA09-11DD9DEBDD36.lukitus
- <STUBS_DIR>\l2\lukitus-3891.htm
- %HOMEPATH%\Desktop\lukitus.htm
- %HOMEPATH%\Desktop\lukitus.bmp
- <STUBS_DIR>\lin\RYIIIXUY-6ATE-NGDY-78B25CC6-66275CAFC9C2.lukitus
- <STUBS_DIR>\lin\lukitus-3ecc.htm
- C:\Documents and Settings\LocalService\Local Settings\<INETFILES>\Content.IE5\RYIIIXUY-6ATE-NGDY-6AD8E9B7-08C4DAD491C6.lukitus
- C:\Far2\lukitus-f27d.htm
- C:\lukitus-a646.htm
- C:\Documents and Settings\Default User\Templates\lukitus-2b89.htm
- %HOMEPATH%\Templates\lukitus-fb2f.htm
- <STUBS_DIR>\lukitus-2def.htm
- C:\Documents and Settings\LocalService\Cookies\RYIIIXUY-6ATE-NGDY-E63DBAC0-CD1BA9DF677B.lukitus
- C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\RYIIIXUY-6ATE-NGDY-FB2EEC20-DB8B126BB61B.lukitus
- C:\Far2\Addons\lukitus-a317.htm
- C:\Documents and Settings\Default User\lukitus-a59a.htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\GE6MVMMD\desktop.ini
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\4L2NCLU3\desktop.ini
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\6LUDSDWL\desktop.ini
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\89SB8VEF\desktop.ini
- из <Полный путь к файлу> в %TEMP%\sys1.tmp
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'ShImgVw:CPreviewWnd' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''