Техническая информация
- %TEMP%\nsgd9d7.tmp\userinfo.dll
- %TEMP%\nsgd9d7.tmp\access40.dll
- %TEMP%\~dc2a.tmp
- %TEMP%\~dc2b.cmd
- %TEMP%\nsgd9d7.tmp\system.dll
- %TEMP%\nsgd9d7.tmp\iob_english.ini
- %TEMP%\nsgd9d7.tmp\iob_russian.ini
- %TEMP%\nsgd9d7.tmp\ioc_english.ini
- %TEMP%\nsgd9d7.tmp\ioc_russian.ini
- %TEMP%\nsgd9d7.tmp\iod_english.ini
- %TEMP%\nsgd9d7.tmp\iod_russian.ini
- %TEMP%\nsgd9d7.tmp\langdll.dll
- %TEMP%\~dc2a.tmp
- 'wi###tep.com':80
- http://www.wi###tep.com/checknewversion/A260126492301A0687053696969705310a
- DNS ASK wi###tep.com
- ClassName: 'MS_WINHELP' WindowName: ''
- '%TEMP%\~dc2a.tmp' checknewversion 2601264923010a \B
- '%WINDIR%\syswow64\cmd.exe' \c %TEMP%\~DC2B.cmd (со скрытым окном)