Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\svohost.lnk
- '%TEMP%\svshost.exe'
- '<SYSTEM32>\netsh.exe' Advfirewall set allprofiles state off
- '%TEMP%\svohost.exe'
- %TEMP%\aut3.tmp
- %TEMP%\svshost.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\ftplog[1]
- %TEMP%\svshost.exe
- %TEMP%\svohost.exe
- %TEMP%\aut1.tmp
- <Текущая директория>\ImageSearchDLL.dll
- %TEMP%\aut2.tmp
- %TEMP%\svshost.dll
- %TEMP%\aut3.tmp
- %TEMP%\aut1.tmp
- %TEMP%\aut2.tmp
- %TEMP%\svshost.dll
- 'li#####h2016.xtgem.com':80
- 'gg.gg':80
- http://li#####h2016.xtgem.com/ftplog
- http://gg.gg/autoit
- DNS ASK li#####h2016.xtgem.com
- DNS ASK gg.gg
- ClassName: 'Shell_TrayWnd' WindowName: ''