Техническая информация
- '<SYSTEM32>\wscript.exe' "C:\Earth\ConvertShort.vbe"
- '%WINDIR%\explorer.exe' c:\Earth\ConvertShort.vbe
- <SYSTEM32>\wermgr.exe
- C:\earth\convertshort.vbe
- C:\earth\contactmanager.dll
- http://wt###myip.com/text
- DNS ASK wt###myip.com
- DNS ASK 19#.###.#11.95.zen.spamhaus.org
- DNS ASK 19#.###.#11.95.cbl.abuseat.org
- '<SYSTEM32>\wscript.exe' "C:\Earth\ConvertShort.vbe"' (со скрытым окном)
- '<SYSTEM32>\rundll32.exe' C:\Earth\ContactManager.dll,DllRegisterServer
- '<SYSTEM32>\wermgr.exe'