Техническая информация
- '%PROGRAM_FILES%\NetMeeting\winhlp.exe'
- '%WINDIR%\explorer.exe'
- %WINDIR%\explorer.exe
- %TEMP%\nsn3.tmp\SelfDel.dll
- %PROGRAM_FILES%\NetMeeting\winhlp.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\cl[1].php
- <SYSTEM32>\somarshal.dat
- %PROGRAM_FILES%\NetMeeting\WndHook.dll
- %TEMP%\nsn3.tmp\KillProcDLL.dll
- %TEMP%\nsg2.tmp
- %PROGRAM_FILES%\NetMeeting\httpapi.dll
- %PROGRAM_FILES%\NetMeeting\HtmlPeek.dll
- %TEMP%\nsn3.tmp\SelfDel.dll
- %TEMP%\nsn3.tmp\KillProcDLL.dll
- 'cl.###system.com':80
- 'r.###ntech.com':1207
- 'localhost':1036
- cl.###system.com/cl.php?fi####################################################################
- DNS ASK cl.###system.com
- DNS ASK r.###ntech.com