Technical Information
- '<SYSTEM32>\verclsid.exe' /C {BDEADF00-C265-11D0-BCED-00A0C90AB50F} /I {000214E6-0000-0000-C000-000000000046} /X 0x401
- C:\Documents\user\locals~1\temp\~df8615.tmp
- C:\Documents\user\locals~1\temp\winword.log
- C:\Documents\user\locals~1\temp\wecerr.txt
- %HOMEPATH%\nethood\my web sites on msn\desktop.ini
- %HOMEPATH%\nethood\my web sites on msn\target.lnk
- 'se##ra.ru':80
- http://se##ra.ru/_vti_inf.html
- http://se##ra.ru/USER3/sorry/luggage.dot
- http://se##ra.ru/static/frontend-parking/ParkingPage.f3a42e12de40e2d45a4b.css
- DNS ASK se##ra.ru
- ClassName: 'Ghost' WindowName: ''