Техническая информация
- '<SYSTEM32>\regsvr32.exe' %WINDIR%\svchosts.dll
- '%WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe' %WINDIR%\addins\framework4.dll /codebase /silent
- '<SYSTEM32>\rundll32.exe' shell32.dll,Control_RunDLL %TEMP%\baixar.cpl
- %WINDIR%\svchosts.dll
- %WINDIR%\addins\framework4.dll
- %TEMP%\baixar.cpl
- <Полный путь к вирусу>
- '21#.#45.193.27':80
- 'sm###.uol.com.br':587
- '21#.#45.193.20':80
- 'il####romote.com':80
- il####romote.com/infMasterIII/saveinf.php?id##########################
- 21#.#45.193.20/svchosts.dll
- 21#.#45.193.20/framework4.dll
- 21#.#45.193.27/envia.php
- DNS ASK sm###.uol.com.br
- DNS ASK il####romote.com
- ClassName: 'MS_WINHELP' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'