Техническая информация
- '%CommonProgramFiles%\FaIv.exe'
- '%CommonProgramFiles%\sv0hoat.exe'
- '<SYSTEM32>\cmd.exe' /c 1567896.bat
- <Текущая директория>\1567896.bat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\cgi_personal_card[1]
- %CommonProgramFiles%\sv0hoat.exe
- %CommonProgramFiles%\FaIv.exe
- %CommonProgramFiles%\sv0hoat.exe
- 'r.###ne.qq.com':80
- 'localhost':1035
- r.###ne.qq.com/cgi-bin/user/cgi_personal_card?ui###################
- DNS ASK r.###ne.qq.com