Техническая информация
- '<SYSTEM32>\ntvdm.exe' -f -i1
- '<SYSTEM32>\cmd.exe' /c ""C:\25.bat" "
- '<SYSTEM32>\svchost.exe'
- '<SYSTEM32>\cmd.exe' /c ""<Текущая директория>\i.bat" "
- <SYSTEM32>\svchost.exe
- %WINDIR%\Temp\scs1.tmp
- C:\25.bat
- %WINDIR%\Temp\scs2.tmp
- <Текущая директория>\i.bat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\utu[1].dat
- C:\services.exe
- %WINDIR%\Temp\scs2.tmp
- C:\services.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\utu[1].dat
- %WINDIR%\Temp\scs1.tmp
- 'al####ternal.info':80
- al####ternal.info/update/utu.dat
- DNS ASK al####ternal.info
- ClassName: 'ConsoleWindowClass' WindowName: 'ntvdm-b84.b88.390001'