Техническая информация
- %WINDIR%\sumario.exe
- %WINDIR%\wintzart.exe
- %WINDIR%\sumario.exe (загружен из сети Интернет)
- %WINDIR%\wintzart.exe (загружен из сети Интернет)
- %WINDIR%\sumario.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\rc-10-2010[1].doc
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\smtsms[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\kldsms[1]
- %WINDIR%\wintzart.exe
- <Полный путь к вирусу>
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\rc-10-2010[1].doc
- 'www.so#####e-neittein.cl':80
- 'www.cr###ara.org.br':80
- 'localhost':1036
- 'localhost':1037
- www.so#####e-neittein.cl/contacto/requiere/.../smtsms
- www.cr###ara.org.br/portal/images/download/rc-10-2010.doc
- www.so#####e-neittein.cl/contacto/requiere/.../kldsms
- DNS ASK www.cr###ara.org.br
- DNS ASK www.so#####e-neittein.cl
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: '' WindowName: 'Iexplorer1'
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''