Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\3d4bdc.dll"",DoWork
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1400' = '00000000'
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\count[1].htm
- %TEMP%\3d4bdc.msi
- %TEMP%\3d4bdc.dll
- 'localhost':1038
- 'www.va###remoli.com':80
- www.va###remoli.com/2011/obj/count.htm?Ob##########
- www.va###remoli.com/2011/obj/news.gif
- DNS ASK www.va###remoli.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''