Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\svchost.exe
- %HOMEPATH%\Start Menu\Programs\Startup\malwox.exe
- '<DRIVERS>\etc\file.exe'
- '%HOMEPATH%\Start Menu\Programs\Startup\svchost.exe'
- '<DRIVERS>\etc\start1.exe'
- '<DRIVERS>\etc\websrv.exe'
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\get_my_ip[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\test_port[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\add_ip[1].php
- <DRIVERS>\etc\websrv.exe
- <DRIVERS>\etc\hоsts
- <DRIVERS>\etc\start1.exe
- <DRIVERS>\etc\file.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\add_ip[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\test_port[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\get_my_ip[1].php
- 'wo###name.ru':80
- wo###name.ru/add_ip.php?ip####
- wo###name.ru/test_port.php?ip#############
- wo###name.ru/get_my_ip.php
- DNS ASK wo###name.ru
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'