Техническая информация
- %TEMP%\DNF梦魇-驱动防封-02-26A.exe
- %TEMP%\z3.exe
- %TEMP%\chen.txt
- %TEMP%\chen.juan
- %TEMP%\tmped.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\ip[1]
- %TEMP%\DNF梦魇-驱动防封-02-26A.exe
- %TEMP%\z3.exe
- <SYSTEM32>\PastNJH0J.sys
- %TEMP%\chen.chen
- %TEMP%\chen.juan
- %TEMP%\tmped.txt
- %TEMP%\chen.chen
- <SYSTEM32>\PastNJH0J.sys
- 'www.sy###tal.com':80
- 'gg####.xhmyey.com':80
- 'localhost':1036
- 'gg####.xhmyey.com':336
- www.sy###tal.com/ip
- DNS ASK www.sy###tal.com
- DNS ASK gg####.xhmyey.com
- ClassName: 'Shell_TrayWnd' WindowName: ''