Техническая информация
- '<SYSTEM32>\wscript.exe' "%TEMP%\Ap0x.vbs"
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\Ap0x[1].vbs
- %TEMP%\Ap0x.vbs
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\Bind_E1X2C8EKBBUNBMTAQSUH[1].Ap0x
- <SYSTEM32>\TurkeyPE.exe
- %WINDIR%\TURKEY.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\TurkeyPE[1].exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\Bind_E1X2C8EKBBUNBMTAQSUH[1].Ap0x
- %TEMP%\~DF132C.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\TurkeyPE[1].exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\Ap0x[1].vbs
- 'www.eu###asean.com':80
- www.eu###asean.com/Ap0x/Crypt/Bind_E1X2C8EKBBUNBMTAQSUH.Ap0x
- www.eu###asean.com/Ap0x/Ap0x.vbs
- www.eu###asean.com/Ap0x/TurkeyPE.exe
- DNS ASK www.eu###asean.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'