Техническая информация
- C:\PPTV.exe (загружен из сети Интернет)
- C:\FunshionInstall.exe (загружен из сети Интернет)
- %PROGRAM_FILES%\Project.exe
- %PROGRAM_FILES%\2011PP.exe
- %PROGRAM_FILES%\PPTV123.exe
- <SYSTEM32>\reg.exe add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Default_Page_URL" /t reg_sz /d http://www.le##.com /f
- <SYSTEM32>\reg.exe add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /t reg_sz /d http://www.le##.com /f
- <SYSTEM32>\cmd.exe /c ""%PROGRAM_FILES%\2345.bat" "
- %WINDIR%\1312611395_6634280_1284967193_20.fsp
- C:\PPTV.exe
- C:\FunshionInstall.exe
- %PROGRAM_FILES%\2345.bat
- %PROGRAM_FILES%\PPTV123.exe
- %PROGRAM_FILES%\2011PP.exe
- %PROGRAM_FILES%\Project.exe
- 'ne#####.funshion.com':80
- 'qq#####09.vpn.stftp.com':80
- ne#####.funshion.com/download/silent/108988/FunshionInstall.exe
- qq#####09.vpn.stftp.com/PPTV.exe
- DNS ASK ne#####.funshion.com
- DNS ASK qq#####09.vpn.stftp.com
- '<IP-адрес в локальной сети>':1036
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''