Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%WINDIR%\Help\svhost.exe' = '%WINDIR%\Help\svhost.exe:*:Enabled:Ftp...'
- '%WINDIR%\Help\svhost.exe'
- '%WINDIR%\Help\svhost.exe' (загружен из сети Интернет)
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram %WINDIR%\Help\svhost.exe Ftp...
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\ico[1].ico
- %WINDIR%\Help\svhost.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\helloninhaa[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\ico[1].ico
- из <Полный путь к вирусу> в %WINDIR%\Help\<Имя вируса>.exe
- 'www.fl###o.com.br':80
- 'na#####07.fileave.com':80
- 'localhost':1036
- 'localhost':1037
- na#####07.fileave.com/ico.ico
- www.fl###o.com.br/helloninhaa
- DNS ASK na#####07.fileave.com
- DNS ASK www.fl###o.com.br
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'IEFrame' WindowName: '(null)'
- ClassName: '' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'