Техническая информация
- %WINDIR%\Tasks\SA.DAT
- <DRIVERS>\kbdclass.sys файлом <DRIVERS>\classlan.txt
- %WINDIR%\info.bat
- %WINDIR%\info.bat (загружен из сети Интернет)
- <SYSTEM32>\cmd.exe /c <Текущая директория>\k.bat
- <SYSTEM32>\ping.exe 127.0.0.1 -2
- <SYSTEM32>\ntsd.exe -c q -p 1116
- <SYSTEM32>\svchost.exe -k netsvcs
- <SYSTEM32>\svchost.exe
- <DRIVERS>\classlan.txt
- <SYSTEM32>\browsewn.dll
- <Текущая директория>\k.bat
- <SYSTEM32>\dllcache\classlan.txt
- <SYSTEM32>\fecllent.dll
- %WINDIR%\browsewn.dll
- %WINDIR%\info.bat
- %WINDIR%\classlan.txt
- %WINDIR%\fecllent.dll
- %WINDIR%\fecllent.dll
- %WINDIR%\info.bat
- %WINDIR%\classlan.txt
- <SYSTEM32>\cryptsvc.dll
- <DRIVERS>\kbdclass.sys
- %WINDIR%\browsewn.dll
- '7y###.91zc.com':21
- 'www.go##g88.cn':80
- 'do##.youkum.cn':80
- do##.youkum.cn/svchost/classlan.txt
- www.go##g88.cn/Cat/Mac.aspx?MA###########################################################################################
- do##.youkum.cn/svchost/fecllent.dll
- do##.youkum.cn/svchost/info.txt
- do##.youkum.cn/svchost/browsewn.dll
- DNS ASK www.go##g88.cn
- DNS ASK 7y###.91zc.com
- DNS ASK do##.youkum.cn
- '<IP-адрес в локальной сети>':1035
- ClassName: '#32770' WindowName: ''
- ClassName: 'Button' WindowName: '?????????????????'
- ClassName: '#32770' WindowName: '????????????????????'
- ClassName: '' WindowName: '?????????????'