Техническая информация
- '%APPDATA%\YahooStartertemp.exe' %TEMP%\YahooStarter_138.exe
- '%TEMP%\YahooStarter_138.exe'
- '<SYSTEM32>\cmd.exe' /c \DelUS.bat
- C:\DelUS.bat
- %APPDATA%\YahooStartertemp.exe
- %TEMP%\tempfile.dat
- %TEMP%\nsr2.tmp\DLLWebCount.dll
- %TEMP%\YahooStarter_138.exe
- %TEMP%\nsr2.tmp\SelfDelete.dll
- %TEMP%\YahooStarter_138.exe
- %TEMP%\nsr2.tmp\SelfDelete.dll
- %TEMP%\nsr2.tmp\DLLWebCount.dll
- 'st###.funtvi.kr':80
- 'localhost':1040
- '22#.#22.140.75':80
- st###.funtvi.kr/receive/DownCountReceive.php?no###############################
- 22#.#22.140.75/request/count.php?mo####################
- DNS ASK st###.funtvi.kr
- ClassName: 'Shell_TrayWnd' WindowName: ''