Техническая информация
- '' (загружен из сети Интернет)
- 'C:\users\public\vbc.exe'
- '%ProgramFiles%\microsoft office\office14\excel.exe' /dde
- %WINDIR%\explorer.exe
- firefox.exe
- Процесс firefox.exe, модуль nss3.dll
- Процесс iexplore.exe, модуль wininet.dll
- %TEMP%\a9rrft925_vido0c_1ck.tmp\has been verified. however img, pdf, doc, .xls
- %TEMP%\c7f.tmp
- C:\users\public\vbc.exe
- C:\users\public\vbc.exe
- '10#.#67.84.254':80
- '1w##jx.top':80
- http://10#.#67.84.254/111722000/vbc.exe
- http://www.1w##jx.top/bk08/?lB##########################################################################################
- DNS ASK 77##666.vip
- DNS ASK 1w##jx.top
- ClassName: 'XLMAIN' WindowName: 'Microsoft Excel (Product Activation Failed) - Book1'
- ClassName: 'XLMAIN' WindowName: ''
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\wininit.exe'
- '%WINDIR%\syswow64\cmd.exe' del "C:\Users\Public\vbc.exe"