Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows Server Host' = '%WINDIR%\Services.exe'
- '<SYSTEM32>\taskkill.exe' /F /IM firefox.exe
- firefox.exe
- %WINDIR%\Services.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\dns[1].txt
- %WINDIR%\confss1.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\index[1].php
- C:\temp_obj.txt
- 'www.to###.com.br':80
- 'www.ac#####abioativa.com':80
- 'localhost':1036
- www.to###.com.br/dns.txt
- www.ac#####abioativa.com/ebay/index.php?PC#########
- DNS ASK www.to###.com.br
- DNS ASK www.ac#####abioativa.com
- ClassName: '(null)' WindowName: '(null)'