Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\IeProtectdisk.lnk
- [<HKLM>\SYSTEM\ControlSet001\Services\AudioSrv] 'Start' = '00000002'
- %PROGRAM_FILES%\IeProtectdisk.exe "<LS_APPDATA>\IEXPLORE.exe"
- <SYSTEM32>\ping.exe 127.1
- %TEMP%\tutetinhyy.dat
- <Текущая директория>\niunqkjhu
- <SYSTEM32>\51e92691.rdb
- <SYSTEM32>\hydvtwhvcv
- <SYSTEM32>\hamqunacok
- <LS_APPDATA>\kill.exe
- %TEMP%\~1.bat
- <LS_APPDATA>\IEXPLORE.exe
- %HOMEPATH%\Local Settings\hrehqwgvgp
- %PROGRAM_FILES%\IeProtectdisk.exe
- %TEMP%\~1.bat
- %HOMEPATH%\Local Settings\hrehqwgvgp
- <SYSTEM32>\hamqunacok
- <SYSTEM32>\hydvtwhvcv
- <Текущая директория>\niunqkjhu
- <LS_APPDATA>\kill.exe
- <LS_APPDATA>\IEXPLORE.exe
- %TEMP%\~1.bat
- 'gt####cd.gicp.net':321
- DNS ASK qu#.#.360.cn
- DNS ASK gt####cd.gicp.net
- DNS ASK co##.f.360.cn
- ClassName: 'SysListView32' WindowName: ''
- ClassName: 'SHELLDLL_DefView' WindowName: ''
- ClassName: 'Progman' WindowName: ''