Техническая информация
- '%PROGRAM_FILES%\%system%\1.exe'
- '<SYSTEM32>\rundll32.exe' "C:\Remoete.dll" WWWW
- '<SYSTEM32>\taskkill.exe' /f /im KsafeTray.exe
- %TEMP%\148140_res.tmp
- C:\Remoete.dll
- %PROGRAM_FILES%\%system%\123.exe
- %PROGRAM_FILES%\%system%\1.exe
- 'mu####u.gicp.net':456
- DNS ASK mu####u.gicp.net
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''