Техническая информация
- '%TEMP%\1.tmp\ho.exe'
- '%HOMEPATH%\in.exe'
- '%TEMP%\1.tmp\123.exe'
- '%TEMP%\1.tmp\ho.exe' (загружен из сети Интернет)
- '<SYSTEM32>\wscript.exe' "%TEMP%\1.tmp\1.vbs"
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 30
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\bat.bat" "
- %HOMEPATH%\in.exe
- %TEMP%\1.tmp\ho.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\de[1]
- %TEMP%\1.tmp\123.exe
- %TEMP%\1.tmp\bat.bat
- %TEMP%\1.tmp\1.vbs
- %TEMP%\1.tmp\in.exe
- %TEMP%\1.tmp\1.vbs
- %TEMP%\1.tmp\bat.bat
- %TEMP%\1.tmp\123.exe
- %TEMP%\1.tmp\in.exe
- 'localhost':1040
- 'ar#####ffr.hopto.org':80
- 'ge#######endoz.gurcanozturk.com':80
- 'mi##ain.org':80
- 'ro######henderso.were.me':80
- ar#####ffr.hopto.org/get/de
- ge#######endoz.gurcanozturk.com/api/index
- ro######henderso.were.me/api/index
- DNS ASK ge#######endoz.gurcanozturk.com
- DNS ASK ar#####ffr.hopto.org
- DNS ASK mi##ain.org
- DNS ASK ro######henderso.were.me
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: '(null)' WindowName: '8:7#?0&9$(!?@6;#%"?8.3Z?\?)3?+#(-".)?/+%Ez]?sQ???'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'