Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Windows Session Manager Subsystem' = '<Текущая директория>\smss.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Windows Logon Process' = '<Текущая директория>\winlogon.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WinSysModule' = 'dsrss.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'IE Redir' = '<Полный путь к вирусу>'
- <SYSTEM32>\sc.exe delete mctskshd.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\adminclients[1].html
- <SYSTEM32>\drv32dta\pstore_121011_224330.txt
- 'sa###ex.info':80
- 'localhost':1038
- '20#.#6.232.182':80
- sa###ex.info/admin//clients/adminclients.html
- DNS ASK sa###ex.info
- DNS ASK www.microsoft.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''