Техническая информация
- '%TEMP%\2dbdf\2dbdf.exe'
- '<SYSTEM32>\ping.exe' -n 2 127.1
- '<SYSTEM32>\taskkill.exe' /f /im 2dbdf.exe
- '<SYSTEM32>\ping.exe' -n 5 127.1
- %WINDIR%\Explorer.EXE
- ClassName: 'Filemonclass' WindowName: '(null)'
- ClassName: 'Regmonclass' WindowName: '(null)'
- %TEMP%\2dbdf\Change.dll
- %TEMP%\VRy1f4m7vkA1Lgs__2dbdf.dll
- %TEMP%\2dbdf\MsPage.dll
- %TEMP%\2dbdf\Config.ini
- %TEMP%\2dbdf\2dbdf.exe
- %TEMP%\2dbdf\Change.dll
- %TEMP%\2dbdf\2dbdf.exe
- %TEMP%\2dbdf\Config.ini
- 'ge####ata.wicp.net':80
- 'ir###.f3322.org':80
- '12#.#25.114.144':80
- ge####ata.wicp.net/soft/BarClient/SetupPage.asp
- ir###.f3322.org/soft/BarClient/tongji/count.asp?OS##################################################
- 12#.#25.114.144/
- ir###.f3322.org/soft/BarClient/SetupPage.asp
- DNS ASK ge####ata.wicp.net
- DNS ASK ir###.f3322.org
- DNS ASK www.ba##u.com
- ClassName: 'SysListView32' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: '(null)' WindowName: '(null)'
- ClassName: 'SHELLDLL_DefView' WindowName: '(null)'
- ClassName: '4823-00000029' WindowName: '(null)'
- ClassName: '18467-41' WindowName: '(null)'
- ClassName: 'Progman' WindowName: '(null)'