Техническая информация
- '%APPDATA%\hjcc.exe'
- '<SYSTEM32>\verclsid.exe' /C {BDEADF00-C265-11D0-BCED-00A0C90AB50F} /I {000214E6-0000-0000-C000-000000000046} /X 0x401
- C:\Documents\user\locals~1\temp\~df1dbe.tmp
- %APPDATA%\hjcc.exe
- %HOMEPATH%\nethood\my web sites on msn\desktop.ini
- %HOMEPATH%\nethood\my web sites on msn\target.lnk
- C:\Documents\user\locals~1\temp\dw.log
- C:\Documents\user\locals~1\temp\16420f.dmp
- <Текущая директория>\ad561000
- C:\Documents\user\locals~1\temp\~dfaf33.tmp
- C:\Documents\user\locals~1\temp\16420f.dmp
- <PATH_SAMPLE>.xls
- 'po#.tg':80
- '10#.#9.0.182':80
- http://po#.tg/LBL1C
- http://10#.#9.0.182/xampp/wdf/wearegoingtobegoodwithmebecauseireallylovethisallpersonandinotwanttodonothingbecausesheisverybeautifulgirl___iunderstandsheisgoodo.doc
- http://10#.#9.0.182/kung/bin.exe
- DNS ASK po#.tg
- ClassName: 'Ghost' WindowName: ''
- ClassName: 'MsoHelp11' WindowName: ''
- ClassName: 'AgentAnim' WindowName: ''
- '%ProgramFiles%\microsoft office\office12\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 440