Техническая информация
- '%WINDIR%\system\wuauclt.exe'
- '%WINDIR%\system\wuauclt.exe' (загружен из сети Интернет)
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\c0decash[1].sys
- <SYSTEM32>\c0decash.sys
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\spy[1].txt
- %WINDIR%\system\wuauclt.exe
- 'www.li###ec.eng.br':80
- www.li###ec.eng.br/img/c0decash.sys
- www.li###ec.eng.br/img/spy.txt
- DNS ASK www.li###ec.eng.br