Техническая информация
- %WINDIR%\syswow64\cmd.exe
- %WINDIR%\conim.exe
- %WINDIR%\svcho.exe
- %WINDIR%\svchost.exe
- %WINDIR%\kavni.exe
- %TEMP%\bt1001.bat
- %WINDIR%\kavs.txt
- %LOCALAPPDATA%\microsoft\internet explorer\msimgsiz.dat
- %TEMP%\bt1001.bat
- %TEMP%\bt1001.bat
- 'yo#9.cn':80
- http://www.yo#9.cn/down/downtj.html
- DNS ASK yo#9.cn
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%WINDIR%\kavni.exe'
- '%WINDIR%\conim.exe'
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\bt1001.bat (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /S /D /c" echo q "