Техническая информация
- %WINDIR%\s.bat
- %WINDIR%\f.bat
- %WINDIR%\s.bat (загружен из сети Интернет)
- %WINDIR%\f.bat (загружен из сети Интернет)
- <SYSTEM32>\rundll32.exe shell32.dll,Control_RunDLL "c:\Install.CpL",
- %WINDIR%\inad.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\inadd[1].dll
- %WINDIR%\s.bat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\s[1].bat
- %WINDIR%\f.bat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\infran[1].dll
- C:\Install.CpL
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\f[1].bat
- %WINDIR%\infran.dll
- 'up####s.boxify.me':80
- 'localhost':1041
- 'localhost':1037
- 'ba#######ora.goodluckwith.us':80
- ba#######ora.goodluckwith.us/inadd.dll
- up####s.boxify.me/90898/s.bat
- ba#######ora.goodluckwith.us/infran.dll
- up####s.boxify.me/92482/f.bat
- DNS ASK up####s.boxify.me
- DNS ASK ba#######ora.goodluckwith.us
- ClassName: '' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'frmlord' WindowName: ''