Техническая информация
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://40#.#.sapo.pt/
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\404.s.sapo[1]
- <Текущая директория>\<Имя вируса>.tmp
- '40#.#.sapo.pt':80
- 'localhost':1038
- '21#.#7.254.121':80
- 40#.#.sapo.pt/
- 21#.#7.254.121/site/arquivo.extensao
- DNS ASK 40#.#.sapo.pt
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: '' WindowName: ''