Техническая информация
- '<SYSTEM32>\ftp.exe' /C echo binary>>g6.dat
- '<SYSTEM32>\ftp.exe' /C echo if not exist GOTO end>>g5.bat
- '<SYSTEM32>\ftp.exe' -s:g6.dat
- '<SYSTEM32>\ftp.exe' -s:g7.dat
- '<SYSTEM32>\ftp.exe' /C echo >>g7.bat
- '<SYSTEM32>\ftp.exe' -s:g1.dat
- '<SYSTEM32>\ftp.exe' -s:g.dat
- '<SYSTEM32>\ftp.exe' -s:g2.dat
- '<SYSTEM32>\ftp.exe' -s:g4.dat
- '<SYSTEM32>\ftp.exe' -s:g3.dat
- <SYSTEM32>\ftp.exe
- <SYSTEM32>\cmd.exe
- %TEMP%\g4.dat
- %TEMP%\g4.bat
- %TEMP%\g5.dat
- %TEMP%\g2.bat
- %TEMP%\g3.dat
- %TEMP%\g3.bat
- %TEMP%\g5.bat
- %TEMP%\g7.bat
- %TEMP%\g8.dat
- %TEMP%\g8.bat
- %TEMP%\g6.dat
- %TEMP%\g6.bat
- %TEMP%\g7.dat
- %TEMP%\g2.dat
- %TEMP%\i.rar
- %TEMP%\nsr2.tmp\System.dll
- %PROGRAM_FILES%\OnlineStp\Unload.exe
- %TEMP%\nsr2.tmp\Base64.dll
- %TEMP%\nsr2.tmp\Inetc.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\iplookup[1].php
- %HOMEPATH%\Start Menu\Programs\OnlineStp\Unload.lnk
- %TEMP%\g.bat
- %TEMP%\g1.dat
- %TEMP%\g1.bat
- %TEMP%\nsr2.tmp\nsProcess.dll
- %TEMP%\nsr2.tmp\ExecCmd.dll
- %TEMP%\g.dat
- %TEMP%\g5.dat
- %TEMP%\g6.dat
- %TEMP%\g7.dat
- %TEMP%\g4.dat
- %TEMP%\g1.dat
- %TEMP%\g2.dat
- %TEMP%\g3.dat
- 'localhost':1045
- 'localhost':1043
- 'localhost':1047
- 'localhost':1051
- 'localhost':1049
- 'localhost':1037
- 'in#.###ol.sina.com.cn':80
- 'www.mu####hiyanji.com':21
- 'localhost':1041
- 'localhost':1039
- in#.###ol.sina.com.cn/iplookup/iplookup.php
- DNS ASK www.mu####hiyanji.com
- DNS ASK in#.###ol.sina.com.cn
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'