Техническая информация
- '' (загружен из сети Интернет)
- '%APPDATA%\conhost.exe'
- %WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe
- %APPDATA%\conhost.exe
- %TEMP%\aut8259.tmp
- %TEMP%\clinton
- %TEMP%\aut8288.tmp
- %TEMP%\exhilaratingly
- %TEMP%\aut8259.tmp
- %TEMP%\aut8288.tmp
- '45.##.170.92':80
- http://45.##.170.92/microsoftdesignednewtechnologyforupdateentireofficeversionstokeepavoidbugsonthepcforsecure.Doc
- http://45.##.170.92/exploittttt.exe
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe'