Техническая информация
- '%WINDIR%\Temp\dnf.exe'
- '<SYSTEM32>\notepad.exe'
- '<SYSTEM32>\rundll32.exe' 1.ime,Runed %WINDIR%\temp\dnf.exe
- dnf.exe
- %TEMP%\2.tmp
- %TEMP%\3.dll
- %TEMP%\4.dll
- %WINDIR%\Temp\panlong.exe
- %WINDIR%\Temp\dnf.exe
- %PROGRAM_FILES%\Outlook Express\wad.exe
- %WINDIR%\Temp\dnf.exe
- %TEMP%\2.tmp в <SYSTEM32>\1.ime
- ClassName: 'CicLoaderWndClass' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''