Техническая информация
- '%TEMP%\hwzktu.exe'
- '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE' http://www.go##00.cn/index3.htm
- '<SYSTEM32>\cmd.exe' /c %TEMP%\hnuxzpm.bat
- %TEMP%\hnuxzpm.bat
- %TEMP%\laadub.bat
- %TEMP%\hwzktu.exe
- %TEMP%\laadub.bat в %TEMP%\ghohbmto.bat
- 'localhost':1035
- DNS ASK www.10##u.info