Техническая информация
- %APPDATA%\temp\WKI_V20309S.exe
- %APPDATA%\temp\koreakeyword1.exe
- %APPDATA%\temp\WKI_V20309S.exe (загружен из сети Интернет)
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\WKI_V20309S[1].exe
- %TEMP%\nsw6.tmp\nsCommands3.dll
- %TEMP%\nsw6.tmp\nsCmds2.dll
- %APPDATA%\temp\WKI_V20309S.exe
- %TEMP%\nsa5.tmp
- %APPDATA%\temp\koreakeyword1.exe
- %TEMP%\nso2.tmp
- %TEMP%\nsd3.tmp\nsCmds2.dll
- %TEMP%\nsd3.tmp\nsCommands3.dll
- %TEMP%\nsw6.tmp\nsCommands3.dll
- %APPDATA%\temp\koreakeyword1.exe
- %TEMP%\nsw6.tmp\nsCmds2.dll
- %TEMP%\nsd3.tmp\nsCmds2.dll
- %TEMP%\nsd3.tmp\nsCommands3.dll
- 'ap#.###eankeyword.com':80
- ap#.###eankeyword.com/A0903/WKI_V20309S.exe
- DNS ASK ap#.###eankeyword.com