Техническая информация
- '<SYSTEM32>\WScript.exe' "<Имя диска съемного носителя>:\Program Files\Common\ubnhcfagy.vbs"
- '<SYSTEM32>\wscript.exe' <Текущая директория>\Killme.vbs
- '%WINDIR%\regedit.exe' /s "%CommonProgramFiles%\tk.reg"
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\shell32.dll,OpenAs_RunDLL %WINDIR%\tyyftumxg.dcvgn
- \Device\HarddiskVolume3\Program Files\Common\ubnhcfagy.vbs
- C:\about blank.htm
- <Текущая директория>\Killme.vbs
- %WINDIR%\My.ini
- %CommonProgramFiles%\tk.reg
- %WINDIR%\tyyftumxg.dcvgn
- C:\about blank.htm
- %WINDIR%\tyyftumxg.dcvgn
- %CommonProgramFiles%\tk.reg
- DNS ASK u.###6688.com
- DNS ASK dn#.##ftncsi.com
- DNS ASK up.##36688.com
- ClassName: 'SysListView32' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'SHELLDLL_DefView' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'Progman' WindowName: ''