Техническая информация
- <SYSTEM32>\cmd.exe /c """%TEMP%\2011-07-14 20-16-05 140.bat"" "
- <SYSTEM32>\cmd.exe /c """%TEMP%\2011-07-14 20-16-11 812.bat"" "
- <SYSTEM32>\cmd.exe /c """%TEMP%\2011-07-14 20-16-01 031.bat"" "
- <SYSTEM32>\cmd.exe /c """%TEMP%\РЮёґIE.bat"" "
- <SYSTEM32>\reg.exe add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /t reg_sz /d http://www.xi##o.net/ /f
- %TEMP%\2011-07-14 20-16-01 031.bat
- %HOMEPATH%\Favorites\µ±µ±Нш.url
- %HOMEPATH%\Favorites\МФ±¦Нш.url
- %TEMP%\2011-07-14 20-16-05 140.bat
- %TEMP%\2011-07-14 20-16-27 609.bat
- %HOMEPATH%\Desktop\╠╘▒ж╡╝╣║.URL
- %TEMP%\2011-07-14 20-16-11 812.bat
- %HOMEPATH%\Favorites\МФ±¦µј№є.url
- %PROGRAM_FILES%\РЎУОП·\РЎУОП·.exe
- %PROGRAM_FILES%\РЎУОП·\РЎУОП·tmp.exe
- %TEMP%\РЮёґIE.bat
- %PROGRAM_FILES%\РЎУОП·\taobao.ico
- %PROGRAM_FILES%\РЎУОП·\Xianyu.ico
- %PROGRAM_FILES%\РЎУОП·\DangDangWang.ico
- %PROGRAM_FILES%\РЎУОП·\baidu.ico