Техническая информация
- C:\FunshionInstall.exe (загружен из сети Интернет)
- %PROGRAM_FILES%\Project.exe
- <SYSTEM32>\reg.exe add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Default_Page_URL" /t reg_sz /d http://www.23##.com/?93## /f
- <SYSTEM32>\reg.exe add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /t reg_sz /d http://www.23##.com/?93## /f
- <SYSTEM32>\cmd.exe /c ""%PROGRAM_FILES%\2345.bat" "
- %WINDIR%\1310912320_23623226_1310191696_538.fsp
- C:\FunshionInstall.exe
- %PROGRAM_FILES%\Project.exe
- %PROGRAM_FILES%\2345.bat
- 'ne#####.funshion.com':80
- ne#####.funshion.com/download/silent/105798/FunshionInstall.exe
- DNS ASK ne#####.funshion.com
- ClassName: 'funshion_player_tzdenjohn' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''