Техническая информация
- 'C:\Novapasta\mdsn.exe'
- 'C:\Novapasta\mdsn.exe' (загружен из сети Интернет)
- '<SYSTEM32>\regsvr32.exe' /s "c:\NovaPasta\rEvents.dll"
- '<SYSTEM32>\attrib.exe' +S +H "C:\NovaPasta"
- '<SYSTEM32>\attrib.exe' +S +H "rap das gostosonas .scr"
- '<SYSTEM32>\regsvr32.exe' /s "c:\NovaPasta\BrowserHelper.dll"
- '<SYSTEM32>\regsvr32.exe' /s "<SYSTEM32>\jscript.dll"
- '<SYSTEM32>\regsvr32.exe' /s "<SYSTEM32>\vbscript.dll"
- '<SYSTEM32>\reg.exe' add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DFD91E49-D4B1-4D91-9DD2-99071679654E}"
- C:\Novapasta\rEvents.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\mdsn[1].jpg
- C:\Novapasta\mdsn.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\rEvents[1].jpg
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\BrowserHelper[1].jpg
- C:\Novapasta\BrowserHelper.dll
- %TEMP%\~DF3F2F.tmp
- 'tu###zul.biz':80
- 'localhost':1035
- tu###zul.biz/imagens/mdsn.jpg
- tu###zul.biz/imagens/rEvents.jpg
- tu###zul.biz/imagens/BrowserHelper.jpg
- DNS ASK tu###zul.biz