Техническая информация
- %WINDIR%\zu.exe
- %WINDIR%\tr.exe
- %WINDIR%\zu.exe (загружен из сети Интернет)
- %WINDIR%\tr.exe (загружен из сети Интернет)
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\zu[1].exe
- %WINDIR%\zu.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\rep[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\rep2[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\tr[1].exe
- %WINDIR%\tr.exe
- 'ho##3.net':80
- 'localhost':1037
- '66.##6.72.133':80
- ho##3.net/AsaStat/dat4/zu.exe
- 66.##6.72.133/loader/4/rep.php?r=############
- 66.##6.72.133/loader/4/rep2.php?22####
- ho##3.net/AsaStat/dat4/tr.exe
- DNS ASK ho##3.net