Техническая информация
- %WINDIR%\Temp\funshion.exe
- %WINDIR%\Temp\funshion.exe (загружен из сети Интернет)
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\8888[1]
- %WINDIR%\Temp\funshion.exe
- %TEMP%\temp.txt
- 'www.q7##2.com':80
- 'cd#.##upload.com':80
- 'as##.#21133.info':80
- 'localhost':1038
- www.q7##2.com/8888/
- cd#.##upload.com/down/1124968/funshion.exe
- as##.#21133.info/???#########
- as##.#21133.info/deny.txt
- DNS ASK cd#.##upload.com
- DNS ASK www.q7##2.com
- DNS ASK as##.#21133.info
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''