Техническая информация
- '%TEMP%\01.exe' /S
- '%TEMP%\ie.exe'
- '%TEMP%\c5.exe'
- '%TEMP%\01.exe' (загружен из сети Интернет)
- '%WINDIR%\regedit.exe' /S %WINDIR%\RegText.reg
- %WINDIR%\RegText.reg
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\01[1].exe
- %TEMP%\01.exe
- %TEMP%\ie.exe
- %TEMP%\c5.exe
- %PROGRAM_FILES%\Internet Explorer\Connection Wizard\iexplore.exe
- %TEMP%\ie.exe
- 't.##ad.com':80
- 'localhost':1037
- t.##ad.com/01.exe
- DNS ASK t.##ad.com
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''