Техническая информация
- '<SYSTEM32>\com\sgjc.exe'
- '<SYSTEM32>\gth29501.exe' %WINDIR%\fonts\ComRes.dll ins <SYSTEM32>\com\sgjc.exe
- '<SYSTEM32>\apiload.exe'
- '<SYSTEM32>\apxload.exe'
- '<SYSTEM32>\apxload.exe' 123
- '<SYSTEM32>\conhost.exe'
- '<SYSTEM32>\PING.EXE' 127.1 -n 8
- '<SYSTEM32>\PING.EXE' 127.1 -n 3
- Библиотека-обработчик для всех процессов: %WINDIR%\fonts\ComRes.dll
- elementclient.exe
- %WINDIR%\Fonts\ComRes.dll
- C:\2.bat
- <SYSTEM32>\mmsfc1.dll
- <SYSTEM32>\gth29501.exe
- %WINDIR%\Fonts\gth29501.fon
- %WINDIR%\Fonts\gth29501.ttf
- <SYSTEM32>\apiload.exe
- <SYSTEM32>\apxload.exe
- <SYSTEM32>\com\sgjc.exe
- C:\3.bat
- \Device\HarddiskVolume3\IO.SYS
- \Device\HarddiskVolume3\IO.SYS
- <SYSTEM32>\apiload.exe
- <SYSTEM32>\apxload.exe
- <SYSTEM32>\com\sgjc.exe
- %WINDIR%\Temp\~DF501AEB4D716E5AA1.TMP
- %TEMP%\~DF2B2E94E36304710C.TMP
- DNS ASK dn#.##ftncsi.com
- DNS ASK www.fg##chr.cn
- ClassName: 'Shell_TrayWnd' WindowName: ''