Техническая информация
- '<SYSTEM32>\regsvr32.exe' <SYSTEM32>\dm.dll /s
- %TEMP%\3.tmp
- <SYSTEM32>\dm.dll
- %TEMP%\2.tmp
- <SYSTEM32>\BackInC.sys
- %TEMP%\1.tmp
- %TEMP%\2.tmp
- %TEMP%\3.tmp
- <SYSTEM32>\BackInC.sys
- %TEMP%\1.tmp
- 'cf###xin.com':80
- cf###xin.com/???#####
- DNS ASK cf###xin.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'