Техническая информация
- <LS_APPDATA>\In.exe "http://www.xu###i100.com/msn/software/partner/w/bibibei12.exe"
- %TEMP%\wscrm.exe "%TEMP%\amc\temp.vbs" "%TEMP%\amc\master.ncq"
- <LS_APPDATA>\663168-1.exe
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.95##1.net/1.htm
- %TEMP%\amc\temp.vbs
- %TEMP%\amc\master.ncq
- %TEMP%\wscrm.exe
- <SYSTEM32>\Taoy.ico
- <LS_APPDATA>\In.exe
- %TEMP%\~1.bat
- %TEMP%\nsk3.tmp
- <LS_APPDATA>\663168-1.exe
- %TEMP%\~1.bat
- 'localhost':1036
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''