Техническая информация
- '%WINDIR%\Temp\k.exe'
- '%WINDIR%\Temp\t.exe'
- '%WINDIR%\Temp\l.exe'
- '%WINDIR%\Temp\t.exe' (загружен из сети Интернет)
- '%WINDIR%\Temp\l.exe' (загружен из сети Интернет)
- '%WINDIR%\Temp\k.exe' (загружен из сети Интернет)
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\server[1].exe
- %WINDIR%\Temp\t.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\wstat[1].php
- %WINDIR%\Temp\k.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\server[1].exe
- %WINDIR%\Temp\l.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\server[1].exe
- 'da###d.co.uk':80
- 'no####club.6600.org':80
- 'co##.2288.org':80
- 'localhost':1036
- 'gr######-ecards.7766.org':80
- da###d.co.uk/images/usa/server.exe
- no####club.6600.org/usa/wstat.php?st#####
- gr######-ecards.7766.org/usa/server.exe
- co##.2288.org/usa/server.exe
- DNS ASK da###d.co.uk
- DNS ASK no####club.6600.org
- DNS ASK gr######-ecards.7766.org
- DNS ASK co##.2288.org