Техническая информация
- %PROGRAM_FILES%\Internet Explorer\SIGNUP\vista.com
- C:\ProgramData\bundas.exe
- %PROGRAM_FILES%\Internet Explorer\SIGNUP\vista.com (загружен из сети Интернет)
- <SYSTEM32>\rundll32.exe <SYSTEM32>\shell32.dll,OpenAs_RunDLL C:\ProgramData\sultra.pps
- <SYSTEM32>\cmd.exe /c ""C:\ProgramData\bundas.bat" "
- %PROGRAM_FILES%\Internet Explorer\SIGNUP\bck.bck
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\download[1].asp
- %PROGRAM_FILES%\Internet Explorer\SIGNUP\vista.com
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\bck[1].bck
- C:\ProgramData\bundas.bat
- C:\ProgramData\bundas.exe
- C:\ProgramData\sultra.pps
- 'uf####apower.com':80
- 'www.00#####acentaurib.com':80
- 'localhost':1037
- uf####apower.com/download.asp?id##
- www.00#####acentaurib.com/www/janba/bck.bck
- DNS ASK uf####apower.com
- DNS ASK www.00#####acentaurib.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''