Техническая информация
- <SYSTEM32>\cscript.exe "%TEMP%\qq2.vbs"
- <SYSTEM32>\rundll32.exe "%PROGRAM_FILES%\Outlook Express\msoe\msoejf.dll",Install
- <SYSTEM32>\cscript.exe "%TEMP%\qq1.vbs"
- <SYSTEM32>\wbem\mofcomp.exe -N:root\cimv2 <SYSTEM32>\wbem\asecimv2.mof
- <SYSTEM32>\wbem\asecimv2.mof
- %TEMP%\qq2.vbs
- %TEMP%\tmp2.tmp
- %TEMP%\tmp1.tmp
- %TEMP%\wi115000nd.temp
- %PROGRAM_FILES%\Outlook Express\msoe\msoe.ini
- %TEMP%\qq1.vbs
- %TEMP%\wi122343nd.temp
- %TEMP%\qq1.vbs
- %TEMP%\qq2.vbs
- %TEMP%\tmp2.tmp
- %TEMP%\tmp1.tmp
- <SYSTEM32>\wbem\asecimv2.mof
- 'ch####ng.3322.org':8080
- DNS ASK ch####ng.3322.org