Техническая информация
- %WINDIR%\ctfmon.exe
- <SYSTEM32>\cmd.exe /c c:\emsf3.bat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\sa[1].txt
- C:\tmp.dat
- C:\emsf3.bat
- %WINDIR%\ctfmon.exe
- <DRIVERS>\NtfdDisk.sys
- C:\tmp.dat
- <DRIVERS>\NtfdDisk.sys
- 'mm##.#ovemmll.cn':80
- 'localhost':1037
- 'www.go##le.cn':80
- mm##.#ovemmll.cn/sa.txt
- DNS ASK mm##.#ovemmll.cn
- DNS ASK www.go##le.cn