Техническая информация
- '%TEMP%\kingsoftkonline\KINSTALLERS_66_47367.exe' /s
- '%PROGRAM_FILES%\Windows NT\KINSTALLERS_66_47367.exe'
- '%TEMP%\kingsoftkonline\KINSTALLERS_66_47367.exe' (загружен из сети Интернет)
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /d "http://www.du##.com/?un#########" /f
- '<SYSTEM32>\cmd.exe' /c ""%PROGRAM_FILES%\Windows NT\s.bat" "
- %PROGRAM_FILES%\Windows NT\s.bat
- %TEMP%\kingsoftkonline\KINSTALLERS_66_47367.exe.tmp
- %PROGRAM_FILES%\Windows NT\KINSTALLERS_66_47367.exe
- %PROGRAM_FILES%\Windows NT\使用说明.txt
- %PROGRAM_FILES%\Windows NT\s.bat
- %TEMP%\kingsoftkonline\KINSTALLERS_66_47367.exe.tmp в %TEMP%\kingsoftkonline\KINSTALLERS_66_47367.exe
- 'd.#####.ijinshan.com':80
- 'bo.###a.net:8080':80
- d.#####.ijinshan.com/duba/link/grthKAVSETUPS_66_0.exe
- bo.###a.net:8080/pagetracer2/duba/__utm.gif?01#########################################################################################################################
- DNS ASK d.#####.ijinshan.com
- DNS ASK bo.###a.net:8080
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'