Техническая информация
- '%TEMP%\facebox.exe' (загружен из сети Интернет)
- '%TEMP%\facebox.exe'
- %TEMP%\avast.exe
- %HOMEPATH%\Desktop\Conta Prime.url
- %TEMP%\facebox.exe
- %TEMP%\face.exe
- %TEMP%\dealply301212.exe
- 'wp#d':80
- 'www.pr####ireweb.com':80
- 'localhost':1038
- http://www.pr####ireweb.com/090113download/avast.exe
- http://www.pr####ireweb.com/090113download/facebox.exe
- http://www.pr####ireweb.com/090113download/conta.url
- http://www.pr####ireweb.com/090113stats/confir.htm
- http://11#.#11.111.2/wpad.dat via wp#d
- http://www.pr####ireweb.com/090113stats/090113ip.htm
- http://www.pr####ireweb.com/090113download/dealply301212.exe
- http://www.pr####ireweb.com/090113download/face.exe
- DNS ASK wp#d
- DNS ASK www.pr####ireweb.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''