Техническая информация
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\eBayТЧИ¤--И«ЗтЙМЖ·Т»НшґтѕЎ.lnk
- <SYSTEM32>\cmd.exe /c ""c:\RemoveES.bat" "
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\kugoo4[1].php
- C:\temp.html
- C:\RemoveES.bat
- C:\eBayТЧИ¤--И«ЗтЙМЖ·Т»НшґтѕЎ.lnk
- %HOMEPATH%\Desktop\eBayТЧИ¤--И«ЗтЙМЖ·Т»НшґтѕЎ.lnk
- %HOMEPATH%\Start Menu\eBayТЧИ¤--И«ЗтЙМЖ·Т»НшґтѕЎ.lnk
- %HOMEPATH%\Start Menu\Programs\eBayТЧИ¤--И«ЗтЙМЖ·Т»НшґтѕЎ.lnk
- C:\temp.html
- 'eb##.#isswin.com':80
- 'localhost':1035
- eb##.#isswin.com/kugoo4.php
- DNS ASK eb##.#isswin.com