Техническая информация
- '%WINDIR%\Resources\conimes.exe'
- '<SYSTEM32>\cmd.exe' /c ""%WINDIR%\inf\list.bat" "
- '<SYSTEM32>\tasklist.exe'
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\inf\list.bat
- iexplore.exe
- %WINDIR%\Debug\ONE
- %WINDIR%\inf\Ding.html
- %WINDIR%\inf\11.html
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\2308329[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\17058289[1].js
- %WINDIR%\inf\list.bat
- %WINDIR%\Resources\conimes.exe
- %WINDIR%\inf\list.txt
- %WINDIR%\inf\33.html
- %WINDIR%\inf\22.html
- %WINDIR%\Resources\conimes.exe
- %WINDIR%\inf\list.txt
- '11#.#25.94.108':8080
- 'www.cj#.cn':80
- 'js.##ers.51.la':80
- 'rd#####h.qiniudn.com':80
- 'localhost':1038
- js.##ers.51.la/2308329.js
- www.cj#.cn/aspnet_client/system_web/2_0_50727/123.jpg
- rd#####h.qiniudn.com/0623.jpg
- js.##ers.51.la/17058289.js
- DNS ASK www.cj#.cn
- DNS ASK js.##ers.51.la
- DNS ASK rd#####h.qiniudn.com
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'