Техническая информация
- <SYSTEM32>\cmd.exe /c \DelUS.bat
- <SYSTEM32>\cmd.exe /c \fivi.bat
- C:\fivi.bat
- %HOMEPATH%\Favorites\јоЗО ЅєЖ®ё®Ж®, 11№ш°Ў.url
- %TEMP%\nsy2.tmp\DLLCount3.dll
- C:\DelUS.bat
- %TEMP%\nsy2.tmp\SelfDelete.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\remote[1].php
- %TEMP%\fav_kin04.exe
- %HOMEPATH%\Favorites\»х·Оїо јј»уА» ї©ґВ №®, Gё¶ДП.url
- %HOMEPATH%\Favorites\ґзЅЕАМ ГЈґВ ёрµз ЅєЕёАП, їБјЗ.url
- %HOMEPATH%\Favorites\јоЗОЕЧ¶уЗЗ, dnshop.url
- %TEMP%\nsy2.tmp\DLLCount3.dll
- %TEMP%\nsy2.tmp\SelfDelete.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\remote[1].php
- %TEMP%\fav_kin04.exe
- 'vi###tsoft.net':80
- 'ie###w.co.kr':80
- vi###tsoft.net/counter/insert.php?db####################################################################
- ie###w.co.kr/test/remote.php
- DNS ASK vi###tsoft.net
- DNS ASK ie###w.co.kr