Техническая информация
- %TEMP%\ixp000.tmp\bat8616.exe
- %TEMP%\ixp000.tmp\exe8616.exe
- %WINDIR%\syswow64\lockerplugs.dll
- %APPDATA%\microsoft\internet explorer\quick launch\internet explorer.lnk
- %HOMEPATH%\desktop\internet explorer.lnk
- %WINDIR%\system\705.5475.bat
- %TEMP%\ixp000.tmp\exe8616.exe
- %TEMP%\ixp000.tmp\bat8616.exe
- ClassName: 'Progman' WindowName: ''
- ClassName: 'SHELLDLL_DefView' WindowName: ''
- ClassName: 'SysListView32' WindowName: ''
- '%TEMP%\ixp000.tmp\exe8616.exe'
- '%TEMP%\ixp000.tmp\bat8616.exe'
- '%WINDIR%\syswow64\cmd.exe' /c %WINDIR%\system\705.5475.bat (со скрытым окном)
- '%WINDIR%\syswow64\ping.exe' 127.0.0.1
- '%WINDIR%\syswow64\attrib.exe' +s +h "%WINDIR%\system\LockerPlugs.exe"
- '%TEMP%\ixp000.tmp\exe8616.exe' (со скрытым окном)
- '%TEMP%\ixp000.tmp\bat8616.exe' (со скрытым окном)