Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\office.exe
- '%ProgramFiles%\internet explorer\iexplore.exe' http://down.xingkongjisu.com/flashplayer.htm?52c
- '%ProgramFiles%\internet explorer\iexplore.exe' http://www.on86.com
- %TEMP%\auteb28.tmp
- C:\games.exe
- %WINDIR%\culud.exe
- %TEMP%\auteb28.tmp
- DNS ASK on##.com
- DNS ASK do##.##ngkongjisu.com
- ClassName: '' WindowName: 'culud'
- ClassName: 'NDDEAgnt' WindowName: 'NetDDE Agent'
- ClassName: 'IEFrame' WindowName: ''
- ClassName: '360se_Frame' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- 'C:\games.exe'
- '%WINDIR%\culud.exe'
- '%WINDIR%\culud.exe' (со скрытым окном)