Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '"%PROGRAM_FILES%\stijr\obefnvw.exe"'
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://tc.#22.cc/
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.77##h.com/?uk#
- <SYSTEM32>\services.exe <Имя вируса>.exe
- <SYSTEM32>\svchost.exe -k netsvcs
- %APPDATA%\Mozilla\Firefox\Profiles\przhlnon.default\prefs.js
- <SYSTEM32>\tbhdz.ico
- %APPDATA%\skin.ini
- %TEMP%\zs.bat
- <SYSTEM32>\music.ico
- %TEMP%\lnk.bat
- 'localhost':1036
- DNS ASK do####ad.youbak.com
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''