Техническая информация
- '%WINDIR%\Web\printers\vb\Rar.exe' x -y C:\FirefoxPortable\App\Firefox\fi.rar <SYSTEM32>\config\systemprofile\Doc\fi\
- '%WINDIR%\Web\printers\vb\Rar.exe' x -y %WINDIR%\Web\Printers\vb\update.rar C:\FirefoxPortable\
- '%WINDIR%\Web\printers\vb\setup.exe'
- firefox.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\taiphanmemvaobong[1].txt
- %WINDIR%\Web\printers\vb\setup.exe
- %WINDIR%\Web\printers\vb\taiphanmemvaobong.txt
- %TEMP%\qjzigsn
- %TEMP%\aut4.tmp
- %TEMP%\wftmjxs
- %TEMP%\aut1.tmp
- %TEMP%\aut2.tmp
- %TEMP%\aut3.tmp
- %WINDIR%\Web\printers\vb\Rar.exe
- %WINDIR%\Web\printers\vb\taiphanmemvaobong.txt
- %WINDIR%\Web\printers\vb\setup.exe
- %WINDIR%\Web\printers\vb\Rar.exe
- %TEMP%\aut3.tmp
- %TEMP%\aut4.tmp
- %TEMP%\qjzigsn
- %TEMP%\aut1.tmp
- %TEMP%\wftmjxs
- %TEMP%\aut2.tmp
- 'www.ma####hphonglan.com':80
- www.ma####hphonglan.com/taiphanmemvaobong.txt
- DNS ASK www.ma####hphonglan.com
- ClassName: 'Shell_TrayWnd' WindowName: ''