Техническая информация
- <SYSTEM32>\Del.exe "%PROGRAM_FILES%\Internet Explorer\Sx_server.exe"
- opera.exe
- chrome.exe
- iexplore.exe
- firefox.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\Data[1].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\Search[1].ASP
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\ULU3YH2D\xgj[1].htm
- <SYSTEM32>\Del.exe
- <SYSTEM32>\DelFile.sys
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\dnfqt[1]
- <SYSTEM32>\Del.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\Search[1].ASP
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\Data[1].asp
- <SYSTEM32>\Del.exe
- <SYSTEM32>\DelFile.sys
- 'bb#.#nfqt.com':80
- 'www.dn##t.com':80
- 'localhost':1034
- www.dn##t.com/Search.ASP
- bb#.#nfqt.com/xgj.htm
- www.dn##t.com/
- www.dn##t.com/Data.asp?Da########
- DNS ASK bb#.#nfqt.com
- DNS ASK www.dn##t.com
- '<IP-адрес в локальной сети>':1035
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''