Техническая информация
- %PROGRAM_FILES%\WinRAR\mshta.exe "%PROGRAM_FILES%\WinRAR\hta.hta"
- <SYSTEM32>\msiexec.exe /V
- <SYSTEM32>\msiexec.exe -Embedding 2715D97191D35EFC0E174E52A1E9F8D7
- <SYSTEM32>\msiexec.exe /i "<LS_APPDATA>\shta" /quiet
- <SYSTEM32>\mshta.exe vbscript:createobject("wscript.shell").run("""iexplore""http://cn##.sjt8.com/info.access/?st##########",0)(window.close)
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://cn##.sjt8.com/info.access/?st##########
- %WINDIR%\Installer\MSI3.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\info[1]
- %WINDIR%\Installer\MSI4.tmp
- %PROGRAM_FILES%\WinRAR\mshta.exe
- %PROGRAM_FILES%\WinRAR\hta.hta
- C:\Config.Msi\1ec33.rbs
- <LS_APPDATA>\sqlite3.txt
- <LS_APPDATA>\wget.exe
- %TEMP%\~1.bat
- <LS_APPDATA>\sta
- %WINDIR%\Installer\MSI2.tmp
- %WINDIR%\Installer\1ec30.msi
- <LS_APPDATA>\shta
- %TEMP%\~1.bat
- %WINDIR%\Installer\MSI4.tmp
- %WINDIR%\Installer\MSI3.tmp
- %WINDIR%\Installer\MSI2.tmp
- 'cn##.sjt8.com':80
- 'localhost':1036
- cn##.sjt8.com/info.access/?st##########
- DNS ASK cn##.sjt8.com
- '<IP-адрес в локальной сети>':1037
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''