Техническая информация
- [<HKLM>\SOFTWARE\Classes\exefile\shell\open\command] '' = '%WINDIR%\svchost.com "%1" %*'
- C:\Far2\Far.exe
- %APPDATA%\0.exe
- %APPDATA%\1.exe
- %TEMP%\3582-490\1.exe
- %WINDIR%\svchost.com
- %TEMP%\nse2.tmp\System.dll
- %TEMP%\nse2.tmp\modern-wizard.bmp
- %TEMP%\tmp5023.tmp
- %TEMP%\dw.log
- %TEMP%\2B5F8.dmp
- 'wp#d':80
- 'pa###bin.com':443
- http://11#.#11.111.1/wpad.dat via wp#d
- DNS ASK wp#d
- DNS ASK pa###bin.com
- ClassName: '#32770' WindowName: ''
- '%APPDATA%\0.exe'
- '%APPDATA%\1.exe'
- '%TEMP%\3582-490\1.exe'
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 772