Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\javaupdate.lnk
- %LOCALAPPDATA%\microsoft\internet explorer\iecompatdata\iecompat.nls
- '<SYSTEM32>\rundll32.exe' "%LOCALAPPDATA%\Microsoft\Internet Explorer\IECompatData\iecompat.nls", RaitingSetupUI "<PATH_SAMPLE>.doc" "0" 0 0
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1420
- %LOCALAPPDATA%\microsoft\internet explorer\iecompatdata\iecompat.nls
- <PATH_SAMPLE> .doc
- %TEMP%\1092724.cvr
- 'cu####irenze.com':443
- DNS ASK cu####irenze.com
- '<SYSTEM32>\rundll32.exe' "%LOCALAPPDATA%\Microsoft\Internet Explorer\IECompatData\iecompat.nls", RaitingSetupUI "<PATH_SAMPLE>.doc" "0" 0 0' (со скрытым окном)