Техническая информация
- '<SYSTEM32>\regsvr32.exe' "%WINDIR%\xjava.dll" /s
- '<SYSTEM32>\regsvr32.exe' "%WINDIR%\live2login.dll" /s
- '<SYSTEM32>\regsvr32.exe' "%WINDIR%\google_in.dll" /s
- '<SYSTEM32>\regsvr32.exe' "%WINDIR%\sys_flash.dll" /s
- %WINDIR%\sys_flash.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\hm[1].jpg
- %WINDIR%\xjava.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\npl[1].jpg
- %WINDIR%\google_in.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\bt[1].jpg
- <Полный путь к вирусу>
- 'sm##.#erra.com.br':25
- 'im#####.web40.f1.k8.com.br':80
- 'localhost':1035
- im#####.web40.f1.k8.com.br/hm.jpg
- im#####.web40.f1.k8.com.br/bt.jpg
- im#####.web40.f1.k8.com.br/npl.jpg
- DNS ASK sm##.#erra.com.br
- DNS ASK im#####.web40.f1.k8.com.br
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'