Техническая информация
- '%PROGRAM_FILES%\kupan\Йэј¶іМРт.exe'
- '%PROGRAM_FILES%\kupan\Brmas_pc[bsfnqr].exe'
- '<SYSTEM32>\find.exe' /i "windows xp"
- '<SYSTEM32>\find.exe' /i "windows 7"
- '<SYSTEM32>\wbem\wmic.exe' os get Caption/value
- <Текущая директория>\Read1
- %TEMP%\tmp4.tmp
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp5.tmp
- %TEMP%\tmp3.tmp
- %PROGRAM_FILES%\kupan\Йэј¶іМРт.exe
- %PROGRAM_FILES%\kupan\Brmas_pc[bsfnqr].exe
- %TEMP%\CheckList.dll
- %TEMP%\2868C807.bat
- %TEMP%\nsv2.tmp\System.dll
- %TEMP%\2868C807.bat
- %TEMP%\tmp5.tmp
- %TEMP%\tmp4.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\2[1].3updata
- %TEMP%\2868C807.bat
- %TEMP%\tmp3.tmp
- %TEMP%\nsv2.tmp\System.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\2[1].3updata
- <Текущая директория>\Read1
- 'www.87###2894.com':80
- www.87###2894.com/mokuai/2.3updata
- DNS ASK www.87###2894.com
- ClassName: 'Shell_TrayWnd' WindowName: ''