Техническая информация
- %TEMP%\5l0.exe
- %TEMP%\5l0.exe (загружен из сети Интернет)
- <SYSTEM32>\mshta.exe "%TEMP%\up.hta"
- <SYSTEM32>\wscript.exe "%TEMP%\alltop.vbs"
- <SYSTEM32>\wscript.exe "%TEMP%\mytop.vbs"
- %TEMP%\up.hta
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\s1x2f58f6[1].gif
- %TEMP%\5l0.exe
- %TEMP%\alltop.vbs
- %ALLUSERSPROFILE%\Desktop\Internet Explroer.url
- %TEMP%\mytop.vbs
- %TEMP%\up.hta
- %TEMP%\5l0.exe
- %TEMP%\mytop.vbs
- %TEMP%\~DFCE39.tmp
- %TEMP%\alltop.vbs
- 'up.#l0.net':80
- 'localhost':1035
- up.#l0.net/myup/s1x2f58f6.gif
- DNS ASK up.#l0.net
- ClassName: 'Shell_TrayWnd' WindowName: ''