Техническая информация
- 'C:\ksbinstaller_s_66_59636.exe'
- 'C:\setups_66_66742.exe'
- '%TEMP%\1.tmp\123.exe'
- 'C:\KAVSETUPS_66_100050.exe'
- 'C:\setups_66_66742.exe' (загружен из сети Интернет)
- 'C:\KAVSETUPS_66_100050.exe' (загружен из сети Интернет)
- 'C:\ksbinstaller_s_66_59636.exe' (загружен из сети Интернет)
- '<SYSTEM32>\wscript.exe' "%TEMP%\1.tmp\123.vbs"
- '<SYSTEM32>\ping.exe' -n 3 127.0.0.1
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\setup.bat" "
- C:\ksbinstaller_s_66_59636.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\ksbinstaller_s_66_59636[1].exe
- C:\setups_66_66742.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\jump[1].php
- C:\KAVSETUPS_66_100050.exe
- %TEMP%\1.tmp\123.exe
- %TEMP%\1.tmp\setup.bat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\jump[1].php
- %TEMP%\1.tmp\123.VBS
- %TEMP%\1.tmp\setup.bat
- 'd.#####.ijinshan.com':80
- 'j.#####.ijinshan.com':80
- 'localhost':1036
- d.#####.ijinshan.com/liebao/link/ksbinstaller_s_66_59636.exe
- j.#####.ijinshan.com/jump.php?u_##########
- DNS ASK d.#####.ijinshan.com
- DNS ASK j.#####.ijinshan.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'