Техническая информация
- %TEMP%\nsz2.tmp\ns4.tmp "%TEMP%\nsz2.tmp\tmp0001.exe.exe"
- %TEMP%\nsz2.tmp\tmp0001.exe.exe
- %TEMP%\nsz2.tmp\ns3.tmp "%TEMP%\nsz2.tmp\lzma.exe" d %TEMP%\nsz2.tmp\inetc.bin %TEMP%\nsz2.tmp\inetc.dll
- %TEMP%\nsz2.tmp\lzma.exe d %TEMP%\nsz2.tmp\inetc.bin %TEMP%\nsz2.tmp\inetc.dll
- %TEMP%\nsz2.tmp\tmp0001.exe.exe (загружен из сети Интернет)
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\iw[1]
- %TEMP%\nsz2.tmp\inetc.dll
- %TEMP%\nsz2.tmp\ns4.tmp
- %TEMP%\nsz2.tmp\file.tmp0003
- %TEMP%\nsz2.tmp\inetc.bin
- %TEMP%\nsz2.tmp\lzma.exe
- %TEMP%\nsz2.tmp\ns3.tmp
- %TEMP%\nsz2.tmp\nsExec.dll
- %TEMP%\nsz2.tmp\nsExec.dll
- %TEMP%\nsz2.tmp\lzma.exe
- %TEMP%\nsz2.tmp\tmp0001.exe.exe
- %TEMP%\nsz2.tmp\tmp0001.exe
- %TEMP%\nsz2.tmp\ns4.tmp
- %TEMP%\nsz2.tmp\ns3.tmp
- %TEMP%\nsz2.tmp\inetc.dll
- %TEMP%\nsz2.tmp\inetc.bin
- %TEMP%\nsz2.tmp\file.tmp0003 в %TEMP%\nsz2.tmp\tmp0001.exe
- 'www.in####lwrapper.com':80
- www.in####lwrapper.com/downloads/iw.exe?i=#########
- DNS ASK www.in####lwrapper.com
- ClassName: 'Shell_TrayWnd' WindowName: ''