Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'sbthost' = '%APPDATA%\<Имя вируса>.exe'
- opera.exe
- firefox.exe
- iexplore.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\SL6TKFAX\up[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\pacfig[2].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\ULU3YH2D\up[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\pacfig[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\clientes[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\pacfig[1].txt
- 'us#####s.multimania.es':80
- 'se####oseguro.com':80
- 'www.to##rade.cz':80
- us#####s.multimania.es/elefante1/up.txt
- us#####s.multimania.es/elefante2/up.txt
- www.to##rade.cz/pacfig.txt
- se####oseguro.com/clientes.php?da###################################
- DNS ASK us#####s.multimania.es
- DNS ASK se####oseguro.com
- DNS ASK www.to##rade.cz
- ClassName: 'Indicator' WindowName: ''