Техническая информация
- %WINDIR%\Tasks\USA.bat
- [<HKLM>\SYSTEM\ControlSet001\Services\BITS] 'Start' = '00000002'
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\WR09ET0N\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\2TMJKNC9\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\1DIXTLZ2\wpad[1].dat
- %TEMP%\110468_res.tmp
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\1DIXTLZ2\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\89ABCDEF\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\WR09ET0N\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\2TMJKNC9\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\89ABCDEF\desktop.ini
- <SYSTEM32>\RxmythC.dll
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\1DIXTLZ2\desktop.ini
- 'wpad.localdomain':80
- 'www.ha##er.com':80
- wpad.localdomain/wpad.dat
- www.ha##er.com/ip.txt
- DNS ASK wpad.localdomain
- DNS ASK www.ha##er.com