Техническая информация
- <SYSTEM32>\wscript.exe "%WINDIR%\temp\709808.vbs" 程序运行参数
- %WINDIR%\srchasst\mui\0409\balloon.xsl.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\lclsrch[1].xml
- %WINDIR%\srchasst\mui\0409\lclsrch.xml.tmp
- %TEMP%\aut1.tmp
- %WINDIR%\Temp\709808.vbs
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\balloon[1].xsl
- %WINDIR%\srchasst\mui\0409\balloon.xsl.tmp
- %WINDIR%\srchasst\mui\0409\lclsrch.xml.tmp
- %WINDIR%\Temp\Perflib_Perfdata_7e8.dat
- %TEMP%\aut1.tmp
- %WINDIR%\Temp\709808.vbs
- 'sa.##ndows.com':80
- sa.##ndows.com/sasearch/lclsrch.xml
- sa.##ndows.com/sasearch/balloon.xsl
- DNS ASK sa.##ndows.com
- ClassName: '' WindowName: 'GINA Logon'
- ClassName: '' WindowName: ''