Техническая информация
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe
- %TEMP%\dw.log
- %TEMP%\32DB8.dmp
- %APPDATA%\010112.txt
- %APPDATA%\Sample.lnk
- %APPDATA%\DataWork\<Имя вируса>.exe
- 'am####.no-ip.biz':5632
- 'am####.no-ip.biz':1515
- 'wp#d':80
- wp#d/wpad.dat
- DNS ASK am####.no-ip.biz
- DNS ASK www.download.windowsupdate.com
- DNS ASK wp#d
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'