Техническая информация
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\i9p1hbpu\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\en6v1fra\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\yvg1rcry\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\251r13c5\desktop.ini
- %WINDIR%\wg.txt
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\i9p1hbpu\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\en6v1fra\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\yvg1rcry\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\251r13c5\desktop.ini
- %WINDIR%\wg.txt
- %LOCALAPPDATA%\Microsoft\Windows\<INETFILES>\Content.IE5\desktop.ini
- http://sa##.#wxww.net:820/wg.txt via sa##.ywxww.net
- DNS ASK sa##.ywxww.net
- '%WINDIR%\syswow64\rundll32.exe' InetCpl.cpl,ClearMyTracksByProcess 8' (со скрытым окном)
- '%WINDIR%\syswow64\rundll32.exe' InetCpl.cpl,ClearMyTracksByProcess 8