Техническая информация
- '%HOMEPATH%\poknat\poknat.exe'
- '<SYSTEM32>\ntvdm.exe' -f -i2
- '<SYSTEM32>\tasklist.exe'
- '<SYSTEM32>\ntvdm.exe' -f -i1
- %HOMEPATH%\poknat\poknat.exe
- %WINDIR%\Temp\scs3.tmp
- %WINDIR%\Temp\scs4.tmp
- %WINDIR%\Temp\scs2.tmp
- %HOMEPATH%\poknat\zzz.exe
- %WINDIR%\Temp\scs1.tmp
- %HOMEPATH%\poknat\poknat.exe
- %WINDIR%\Temp\scs3.tmp
- %WINDIR%\Temp\scs4.tmp
- %TEMP%\~DFECA9.tmp
- %WINDIR%\Temp\scs1.tmp
- %WINDIR%\Temp\scs2.tmp
- 'bl###ong.org':80
- bl###ong.org/1.dat
- DNS ASK bl###ong.org
- ClassName: 'ConsoleWindowClass' WindowName: 'ntvdm-a34.a38.3a0002'
- ClassName: 'ConsoleWindowClass' WindowName: 'ntvdm-9d0.9d4.380001'