Техническая информация
- '<SYSTEM32>\regsvr32.exe' /s <SYSTEM32>\dm.dll
- '<SYSTEM32>\regsvr32.exe' /u /s dm.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\5e0d47a999e315074a36d67c[1].html
- <SYSTEM32>\dm.dll
- 'hi.##idu.com':80
- hi.##idu.com/tmpurl/blog/item/5e0d47a999e315074a36d67c.html
- DNS ASK hi.##idu.com
- ClassName: 'Shell_TrayWnd' WindowName: ''