Техническая информация
- '<SYSTEM32>\cmd.exe' /c ""<SYSTEM32>\deltmp.bat" "
- '<SYSTEM32>\rasphone.exe' -d 宽带连接
- '<SYSTEM32>\regsvr32.exe' /s <SYSTEM32>\dm.dll
- '<SYSTEM32>\regsvr32.exe' MSWINSCK.OCX /s
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YFYVABUN\desktop.ini
- <Текущая директория>\IPset.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\85678DA7\desktop.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\CYTETMVS\desktop.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\QNMZ2P6H\desktop.ini
- <SYSTEM32>\dm.dll
- <SYSTEM32>\dnf222.txt
- <SYSTEM32>\volumeid.exe
- <SYSTEM32>\deltmp.bat
- <SYSTEM32>\dialupass.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\QNMZ2P6H\desktop.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\CYTETMVS\desktop.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YFYVABUN\desktop.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\85678DA7\desktop.ini
- '<IP-адрес в локальной сети>':81
- 'localhost':1044
- DNS ASK www.so##.com
- ClassName: '(null)' WindowName: 'Microsoft Windows'
- ClassName: '(null)' WindowName: 'Madu.exe'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: '(null)' WindowName: 'qqlogin.exe'