Техническая информация
- %WINDIR%\Tasks\conime.exe
- '%TEMP%\1.tmp\paopao_68_2065_.exe'
- '%TEMP%\is-KFJJL.tmp\paopao_68_2065_.tmp' /SL5="$400DE,553374,72192,%TEMP%\1.tmp\paopao_68_2065_.exe"
- '%WINDIR%\Tasks\conime.exe'
- '%TEMP%\1.tmp\vv.exe'
- '%TEMP%\2.tmp\v.exe'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\2.tmp\setup.bat" "
- '<SYSTEM32>\ping.exe' -n 3 127.0.0.1
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\setup.bat" "
- %TEMP%\is-KFJJL.tmp\paopao_68_2065_.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\count[1].asp
- C:\boot
- %TEMP%\is-3417G.tmp\_isetup\_RegDLL.tmp
- %TEMP%\is-3417G.tmp\License.txt
- %TEMP%\is-3417G.tmp\Support.dll
- %TEMP%\is-3417G.tmp\_isetup\_shfoldr.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\down[1].txt
- %TEMP%\1.tmp\vv.exe
- %TEMP%\1.tmp\paopao_68_2065_.exe
- %TEMP%\1.tmp\setup.bat
- %TEMP%\1.tmp\beike_55_2065_.exe
- %TEMP%\2.tmp\v.exe
- %TEMP%\2.tmp\setup.bat
- %TEMP%\1.tmp\url.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\count[1].asp
- C:\boot
- %TEMP%\2.tmp\setup.bat
- 'localhost':1039
- 'pa###o.5411.com':80
- 'localhost':1036
- 'tj.##haoche.com':80
- pa###o.5411.com/applist/index154.php
- tj.##haoche.com/count.asp?ma###############
- tj.##haoche.com/down.txt
- DNS ASK pa###o.5411.com
- DNS ASK tj.##haoche.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'