Техническая информация
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\svchost.exe'
- <SYSTEM32>\svchost.exe
- %TEMP%\27f78.tmp
- %TEMP%\2869d.tmp
- <SYSTEM32>\Sys.sys
- %TEMP%\275c2.tmp
- %TEMP%\256e0.tmp
- %TEMP%\25e44.tmp
- %TEMP%\264cd.tmp
- %TEMP%\27f78.tmp
- %TEMP%\2869d.tmp
- <SYSTEM32>\Sys.sys
- %TEMP%\275c2.tmp
- %TEMP%\256e0.tmp
- %TEMP%\25e44.tmp
- %TEMP%\264cd.tmp
- 'li#####ng2014.ys168.com':80
- li#####ng2014.ys168.com/
- DNS ASK li#####ng2014.ys168.com
- ClassName: '' WindowName: '??????'
- ClassName: '' WindowName: 'ЕЭЕЭМГ'
- ClassName: 'Crazy Arcade' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''