Техническая информация
- %TEMP%\nst3.tmp\ymsgr_suite_setup.exe /yfn=a.exe /ybsini=%TEMP%\nst3.tmp\BOOTST~1.INI
- %TEMP%\a.exe
- <SYSTEM32>\ping.exe localhost -n 5
- <SYSTEM32>\cmd.exe /c ""%TEMP%\1.tmp\starter_emulator.bat" "
- [<HKCU>\Software\Yahoo\pager]
- %TEMP%\nsr5.tmp\System.dll
- %TEMP%\nst3.tmp\YExecShell.dll
- %TEMP%\nsr5.tmp\InetLoad_vms.dll
- %TEMP%\nsr5.tmp\ymsgr11_us.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\ymsgr11_us[1].ini
- %TEMP%\nst3.tmp\ymsgr_suite_setup.exe
- <Текущая директория>\a.exe
- %TEMP%\1.tmp\starter_emulator.bat
- %TEMP%\nst3.tmp\System.dll
- %TEMP%\nst3.tmp\Base64.dll
- %TEMP%\nst3.tmp\bootstrap.ini
- %TEMP%\1.tmp\starter_emulator.bat
- '67.##5.160.76':80
- 67.##5.160.76/ycontent/stats.php?ve###############################################################################################
- 67.##5.160.76/msgr/11/ini/ymsgr11_us.ini
- DNS ASK in#####.msg.yahoo.com
- DNS ASK rd.####ware.yahoo.com
- ClassName: 'Shell_TrayWnd' WindowName: ''