Техническая информация
- %WINDIR%\Tasks\Vpnrieu.job
- '<SYSTEM32>\Nbme.exe' "<SYSTEM32>\Nbme.exe",Guvtsovgnx
- '<SYSTEM32>\ipconfig.exe' /flushdns
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\OXM30XM7\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\YN8FED81\desktop.ini
- %TEMP%\~unins7218.bat
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\4T6VMBSF\desktop.ini
- <SYSTEM32>\Nbme.exe
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\456NCT67\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\4T6VMBSF\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\OXM30XM7\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\YN8FED81\desktop.ini
- %WINDIR%\Tasks\Vpnrieu.job
- <SYSTEM32>\Nbme.exe
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\456NCT67\desktop.ini
- <SYSTEM32>\Restore\MachineGuid.txt
- 'im###hut4.cn':80
- 'wi###ounter.net':80
- im###hut4.cn/update/utu.dat
- DNS ASK im###hut4.cn
- DNS ASK wi###ounter.net