Техническая информация
- '%PROGRAM_FILES%\Micrless\notepad1.exe'
- '%PROGRAM_FILES%\Micrless\storm.exe'
- '<SYSTEM32>\wscript.exe' "%PROGRAM_FILES%\del.vbs"
- %PROGRAM_FILES%\Micrless\storm.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\index[1].htm
- %PROGRAM_FILES%\Micrless\notepad1.exe
- %PROGRAM_FILES%\del.vbs
- %PROGRAM_FILES%\Micrless\1.vbs
- %PROGRAM_FILES%\Micrless\notepad.exe
- %PROGRAM_FILES%\Micrless\notepad1.exe
- %PROGRAM_FILES%\Micrless\storm.exe
- %PROGRAM_FILES%\Micrless\notepad.exe
- %PROGRAM_FILES%\del.vbs
- %PROGRAM_FILES%\Micrless\1.vbs
- %PROGRAM_FILES%\del.vbs
- %PROGRAM_FILES%\Micrless\notepad1.exe
- 'ha#.#e00.com':80
- 'localhost':1035
- ha#.#e00.com/d8/woir-cn/index.htm
- DNS ASK ha#.#e00.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''