Техническая информация
- '%WINDIR%\Temp\{428F9FC4-37C8-4C3E-BDE1-2E1DF656BAA2}.exe' -p8grfd@# -d"%WINDIR%\Temp\" -s
- '%WINDIR%\Temp\Main.exe'
- '%WINDIR%\Temp\Temp.exe'
- '%TEMP%\RarSFX0\Setup.exe'
- '%WINDIR%\Temp\{E1707968-8F36-48FC-AC41-6102B7F1D361}.exe' -p%$#%gafE -d"%WINDIR%\Temp\" -s
- %WINDIR%\Temp\Download.dll
- %WINDIR%\Temp\Main.exe
- %TEMP%\sidrunet.tid
- %WINDIR%\Temp\Execute.dll
- %WINDIR%\Temp\{E1707968-8F36-48FC-AC41-6102B7F1D361}.exe
- %TEMP%\RarSFX0\Setup.exe
- %WINDIR%\Temp\{428F9FC4-37C8-4C3E-BDE1-2E1DF656BAA2}.exe
- %WINDIR%\Temp\Temp.exe
- %WINDIR%\Temp\Temp.exe
- %TEMP%\RarSFX0\Setup.exe
- %WINDIR%\Temp\{E1707968-8F36-48FC-AC41-6102B7F1D361}.exe
- %WINDIR%\Temp\{428F9FC4-37C8-4C3E-BDE1-2E1DF656BAA2}.exe
- 'st#.#ndwn.cn':80
- st#.#ndwn.cn/log/ver.asp?ID#####
- DNS ASK st#.#ndwn.cn
- ClassName: 'MS_WINHELP' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'