Техническая информация
- %APPDATA%\Microsoft\Internet Explorer\History
- %TEMP%\dw.log
- %TEMP%\26B91.dmp
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\cookies.sqlite-shm
- %TEMP%\rt.exe
- %TEMP%\Danildh.exe
- %TEMP%\65.exe
- %APPDATA%\Microsoft\Internet Explorer\History
- 'wp#d':80
- 'ip###ger.com':443
- 'kr##ns.ru':80
- 'bi###cket.org':443
- http://11#.#11.111.3/wpad.dat via wp#d
- http://kr##ns.ru/up_d.php
- DNS ASK wp#d
- DNS ASK ip###ger.com
- DNS ASK kr##ns.ru
- DNS ASK bi###cket.org
- '%TEMP%\65.exe'
- '%TEMP%\Danildh.exe'
- '%TEMP%\rt.exe'
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 780