Техническая информация
- %TEMP%\1.tmp\Virus.bat
- %TEMP%\1.tmp\Virus.bat
- 'localhost':1038
- 'we###elp.net':80
- http://www.we###elp.net/ via we###elp.net
- DNS ASK www.we###elp.net
- ClassName: '' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\Virus.bat""
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -nohome
- '<SYSTEM32>\msg.exe' * Haha, hacked :P by Dewag_ www.we###elp.net :P