Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\<Имя вируса>.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\protokoll[1].html
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\updade_link_programm[1].html
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\deine_werbungl[1].html
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\video_programm[1].html
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\newspro[1].html
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\programm_add[1].html
- 'fi###.npage.de':80
- 'localhost':1036
- fi###.npage.de/008630/22/html/protokoll.html
- fi###.npage.de/008630/22/html/updade_link_programm.html
- fi###.npage.de/008630/22/html/deine_werbungl.html
- fi###.npage.de/008630/22/html/video_programm.html
- fi###.npage.de/008630/22/html/newspro.html
- fi###.npage.de/008630/22/html/programm_add.html
- DNS ASK fi###.npage.de
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'