Техническая информация
- file1.exe
- %TEMP%\aut8dcd.tmp
- %TEMP%\file1.exe
- %TEMP%\aut8dde.tmp
- %TEMP%\file2.exe
- %APPDATA%\microsoft\windows\iup41i.cfg
- %APPDATA%\microsoft\windows\iup41i.cfg
- %TEMP%\aut8dcd.tmp
- %TEMP%\aut8dde.tmp
- 'redir.metaservices.microsoft.com':80
- 'onlinestores.metaservices.microsoft.com':80
- http://redir.metaservices.microsoft.com/redir/allservices/?sv################################################################################
- http://onlinestores.metaservices.microsoft.com/serviceswitching/AllServices.aspx?sv################################################################################
- http://onlinestores.metaservices.microsoft.com/bing/bing.xml
- DNS ASK redir.metaservices.microsoft.com
- DNS ASK onlinestores.metaservices.microsoft.com
- ClassName: 'JFWUI2' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- '%TEMP%\file1.exe'
- '%TEMP%\file2.exe'
- '%ProgramFiles(x86)%\windows media player\setup_wm.exe' /RunOnce:%TEMP%\file2.exe (со скрытым окном)