Техническая информация
- "%TEMP%\$ND1.exe" (загружен из сети Интернет)
- <SYSTEM32>\wscript.exe ""%TEMP%\$ND2.vbs"" //B
- %TEMP%\$ND2.tmp
- %TEMP%\$ND2.vbs
- %TEMP%\$ND1.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\winupbg_wp003[1].exe
- %TEMP%\$ND1.tmp
- %TEMP%\$ND2.vbs
- %TEMP%\$ND1.tmp
- %TEMP%\$ND2.vbs
- %TEMP%\$ND1.exe
- %TEMP%\$ND2.tmp
- %TEMP%\$ND1.tmp
- 'www.fd##k.co.kr':80
- www.fd##k.co.kr/mmsv/winup/CP/winupbg_wp003.exe
- DNS ASK www.fd##k.co.kr