Техническая информация
- %WINDIR%\Temp\svchost.exe (загружен из сети Интернет)
- <SYSTEM32>\NQZTLPSPHOBZ\lsass.exe
- %WINDIR%\Temp\tmp~6730658
- %WINDIR%\Temp\svchost.exe
- %WINDIR%\Temp\tmp~342d4cc.exe
- <SYSTEM32>\NQZTLPSPHOBZ\lsass.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\autorun[1].exe
- %WINDIR%\Temp\tmp~342d4cc.exe
- %WINDIR%\Temp\tmp~6730658
- 'gu####2.narod.ru':80
- 'localhost':1037
- gu####2.narod.ru/autorun.exe
- DNS ASK gu####2.narod.ru