Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '╧╡═│▓╣╢б' = '<SYSTEM32>\Result1.vbe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'wextract_cleanup0' = 'rundll32.exe <SYSTEM32>\advpack.dll,DelNodeRunDLL32 "%TEMP%\IXP000.TMP\"'
- <SYSTEM32>\serverl.exe /port:3118 /pass:walwalwal
- %TEMP%\IXP000.TMP\boot.exe
- <SYSTEM32>\ipconfig.exe /all
- <SYSTEM32>\find.exe "Reply from"
- <SYSTEM32>\wscript.exe "<SYSTEM32>\mail3.vbe"
- <SYSTEM32>\reg.exe ADD HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run /v ╧╡═│▓╣╢б /t REG_SZ /d <SYSTEM32>\Result1.vbe /f
- <SYSTEM32>\ping.exe www.qq.com
- <SYSTEM32>\cmd.exe /c ""<SYSTEM32>\system2.bat" "
- <SYSTEM32>\wscript.exe "<SYSTEM32>\Result1.vbe"
- <SYSTEM32>\net1.exe stop sharedaccess
- <SYSTEM32>\net.exe stop sharedaccess
- <SYSTEM32>\raddrv.dll
- <SYSTEM32>\AdmDll.dll
- <SYSTEM32>\mailbody.txt
- <SYSTEM32>\mail3.vbe
- <SYSTEM32>\Result1.vbe
- %TEMP%\IXP000.TMP\boot.exe
- <SYSTEM32>\serverl.exe
- <SYSTEM32>\system2.bat
- %TEMP%\IXP000.TMP\boot.exe
- 'sm##.tom.com':25
- DNS ASK sm##.tom.com
- DNS ASK www.qq.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''