Техническая информация
- <SYSTEM32>\cmd.exe /c ""%APPDATA%\erase.bat" "
- <LS_APPDATA>\dexs.zip
- %APPDATA%\erase.bat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\dexs[1].zip
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\AppLog[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\ver[1].xml
- <LS_APPDATA>\dexs.zip
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\dexs[1].zip
- 'do#####d.u-tab.co.kr':80
- 'localhost':1038
- 'lo#.#-tab.co.kr':80
- do#####d.u-tab.co.kr/dm4/dexs.zip
- do#####d.u-tab.co.kr/dm4/B0/ver.xml
- lo#.#-tab.co.kr/AppLog.php?a=###########################################################################
- DNS ASK do#####d.u-tab.co.kr
- DNS ASK lo#.#-tab.co.kr
- ClassName: 'Shell_TrayWnd' WindowName: ''