Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Нш°ЙјаїШЦч·юОс¶Л' = '<Полный путь к вирусу>'
- ClassName: 'Filemonclass' WindowName: ''
- ClassName: 'Regmonclass' WindowName: ''
- <Текущая директория>\jinjin.ldb
- <Текущая директория>\jinjin.mdb
- %ALLUSERSPROFILE%\Desktop\Io°E?a?OO?·?In¶E.lnk
- <Текущая директория>\jinjin.ldb
- 'ti####w.nist.gov':13
- 'ni###.datum.com':13
- 'ni#####c.glassey.com':13
- 'ji####ip.vicp.net':8889
- 'ut#####.colorado.edu':13
- 'localhost':1039
- DNS ASK ni#####c.glassey.com
- DNS ASK ni#####j.glassey.com
- DNS ASK ni###.##l-ca.truetime.com
- DNS ASK ni###.datum.com
- DNS ASK ji####ip.vicp.net
- DNS ASK ut#####.colorado.edu
- DNS ASK ti####w.nist.gov
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: '<FileDown>'
- ClassName: '' WindowName: '<????????????????>'
- ClassName: '18467-41' WindowName: ''
- ClassName: '4823-00000029' WindowName: ''