Техническая информация
- '<SYSTEM32>\rundll32.exe' InetCpl.cpl,ClearMyTracksByProcess 8
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\taskkill.exe' /f /im <Имя вируса>.exe
- '<SYSTEM32>\dmremote.exe'
- '<SYSTEM32>\cmd.exe' /c go1.bat
- <SYSTEM32>\dmremote.exe
- <Текущая директория>\go1.bat
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- %TEMP%\~DF8377.tmp
- 'li#####ro.blogspot.com':80
- 'www.gi##gho.net':80
- 'la###him.com':80
- 'li######02.googlecode.com':80
- 'localhost':1039
- 'pl##.##ngdonggame.net':80
- 'localhost':1043
- li#####ro.blogspot.com/
- la###him.com/
- pl##.##ngdonggame.net/drive/hosts.ics
- li######02.googlecode.com/svn/trunk/LIKECF.HTML
- DNS ASK www.gi##gho.net
- DNS ASK la###him.com
- DNS ASK li#####ro.blogspot.com
- DNS ASK pl##.##ngdonggame.net
- DNS ASK li######02.googlecode.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'ThunderRT6FormDC' WindowName: 'CROSSFIRE TOOL'
- ClassName: '' WindowName: ''