Техническая информация
- <LS_APPDATA>\qb0201FA.1E\.vbs
- %TEMP%\2880FXGA.bat
- %TEMP%\2880FXGA.bat
- <LS_APPDATA>\qb0201FA.1E\.vbs
- %TEMP%\2880FXGA.bat
- 'dn##dex.com':80
- 'localhost':1038
- http://www.dn##dex.com/ via dn##dex.com
- DNS ASK www.dn##dex.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- '<SYSTEM32>\cmd.exe' /S /D /c" copy /-y "<DRIVERS>\etc\hosts" %ALLUSERSPROFILE%"
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -nohome
- '<SYSTEM32>\cmd.exe' /S /D /c" echo n "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\2880FXGA.bat" <Полный путь к файлу>"
- '<SYSTEM32>\mode.com' 48,10