Техническая информация
- '%WINDIR%\zdstem_000.exe'
- '%WINDIR%\zdstem_000.exe' (загружен из сети Интернет)
- '<SYSTEM32>\regsvr32.exe' /s "<SYSTEM32>\MSINET.OCX"
- '<SYSTEM32>\regsvr32.exe' /s "<SYSTEM32>\msvbvm60.dll"
- '<SYSTEM32>\regsvr32.exe' /s "<SYSTEM32>\winhttp.dll"
- '<SYSTEM32>\regsvr32.exe' /s "<SYSTEM32>\MSWINSCK.OCX"
- '<SYSTEM32>\regsvr32.exe' /s "<SYSTEM32>\oleaut32.dll"
- '<SYSTEM32>\regsvr32.exe' /s "<SYSTEM32>\COMCAT.DLL"
- '<SYSTEM32>\regsvr32.exe' /s "<SYSTEM32>\SendEmail.dll"
- '<SYSTEM32>\regsvr32.exe' /s "<SYSTEM32>\olepro32.dll"
- '<SYSTEM32>\regsvr32.exe' /s "<SYSTEM32>\stdole2.tlb"
- %WINDIR%\000zdcfg\svchost.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\svchost[1].exe
- %WINDIR%\000zdcfg\spoolsv.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\spoolsv[1].exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\zdstem_000[1].exe
- %TEMP%\RGI1.tmp
- %WINDIR%\winZdstem.exe
- %WINDIR%\zdstem_000.exe
- %TEMP%\RGI1.tmp
- '17#.#25.21.94':80
- 'localhost':1036
- 17#.#25.21.94/home/zomb/spoolsv.exe
- 17#.#25.21.94/home/zomb/svchost.exe
- 17#.#25.21.94/home/zomb/zdstem_000.exe