Техническая информация
- <SYSTEM32>\regsvr32.exe /s %WINDIR%\bfcr8212.dll
- <SYSTEM32>\sdbinst.exe -q "%PROGRAM_FILES%\bfcr3329.sdb"
- <SYSTEM32>\regsvr32.exe /s bfcr4.ocx
- %PROGRAM_FILES%\cliente.exe
- <SYSTEM32>\fundo.jpg
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\SL6TKFAX\cliente1[1].jpg
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\cadastro[1].htm
- %WINDIR%\bfcr8212.dll
- <SYSTEM32>\bfcr4.ocx
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\act_img[1].jpg
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\scr_img[1].jpg
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\ULU3YH2D\rem_imgc1[1].jpg
- %PROGRAM_FILES%\bfcr3329.sdb
- 'cl####e1.cwsurf.de':80
- 'gl####ews.hdfree.in':80
- 'localhost':1037
- gl####ews.hdfree.in/aspnet/rem_imgc1.jpg
- gl####ews.hdfree.in/aspnet/cliente1.jpg
- gl####ews.hdfree.in/aspnet/act_img.jpg
- gl####ews.hdfree.in/aspnet/scr_img.jpg
- cl####e1.cwsurf.de/cadastro.php
- DNS ASK cl####e1.cwsurf.de
- DNS ASK gl####ews.hdfree.in