Техническая информация
- %WINDIR%\Temp\Lsass.exe
- <SYSTEM32>\cmd.exe /c c:\delself.bat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\fuck[1].txt
- C:\delself.bat
- %WINDIR%\Temp\Lsass.exe
- %WINDIR%\Temp\xitele.dll
- %WINDIR%\Temp\Lsass.exe
- 'www.yi##777.com':80
- www.yi##777.com/xxx/fuck.txt
- DNS ASK www.yi##777.com