Техническая информация
- 'C:\exiplores\iNumberInf.exe'
- 'C:\exiplores\iLive.exe'
- '%WINDIR%\Anexo1.exe'
- 'C:\exiplores\iConfig.dll'
- 'C:\exiplores\iLive.exe' (загружен из сети Интернет)
- 'C:\exiplores\iConfig.dll' (загружен из сети Интернет)
- 'C:\exiplores\iNumberInf.exe' (загружен из сети Интернет)
- '<SYSTEM32>\regsvr32.exe' /s C:\exiplores\iMega.dll
- '<SYSTEM32>\reg.exe' add "http://or##rl.com/"
- '<SYSTEM32>\attrib.exe' +S +H "Form1"
- '<SYSTEM32>\attrib.exe' +S +H "C:\exiplores"
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\shell32.dll,OpenAs_RunDLL %WINDIR%\SatisfazerMulher.pps
- '<SYSTEM32>\cmd.exe' /c ""%WINDIR%\santa.bat" "
- '<SYSTEM32>\regsvr32.exe' /s "<SYSTEM32>\vbscript.dll"
- '<SYSTEM32>\regsvr32.exe' /s "<SYSTEM32>\jscript.dll"
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\10u[1]
- C:\exiplores\iMega.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\10s[1]
- C:\exiplores\iLive.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\10t[1]
- C:\exiplores\iNumberInf.exe
- %WINDIR%\Anexo1.exe
- %WINDIR%\SatisfazerMulher.pps
- %WINDIR%\santa.bat
- C:\exiplores\iConfig.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\10r[1]
- %TEMP%\~DF5EC4.tmp
- 'or##rl.com':80
- 'localhost':1036
- or##rl.com/10u
- or##rl.com/10t
- or##rl.com/10r
- or##rl.com/10s
- DNS ASK or##rl.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''