Техническая информация
- %ProgramFiles%\internet explorer\poweriso38.exe
- %ProgramFiles%\internet explorer\svchost.exe
- %TEMP%\nsn33c.tmp
- %TEMP%\nsc34c.tmp\options.ini
- %TEMP%\nsc34c.tmp\system.dll
- %WINDIR%\syswow64\comsa32.sys
- 'bf##.com':8392
- '74.#4.89.66':80
- DNS ASK bf##.com
- DNS ASK co####zq6.vicp.net
- DNS ASK cn#####stersblog.com
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'SCDEMUAPP_C2C80BFA WNDCLASS' WindowName: ''
- '%ProgramFiles%\internet explorer\svchost.exe'
- '%ProgramFiles%\internet explorer\poweriso38.exe'