Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ServiceSSH' = '<Полный путь к вирусу>'
- [<HKCU>\Software\Microsoft\MessengerService]
- %PROGRAM_FILES%\atr10.ini
- 'ma########.dominiotemporario.com':80
- 'ma########1.dominiotemporario.com':80
- ma########.dominiotemporario.com/ver.jpg
- ma########1.dominiotemporario.com/j1/contador3.php
- DNS ASK ma########.dominiotemporario.com
- DNS ASK ma########1.dominiotemporario.com
- ClassName: '' WindowName: 'Bem-vindo ao Windows Live Messenger'
- ClassName: '' WindowName: 'Windows Live Hoje'
- ClassName: '' WindowName: 'MSN Hoje'
- ClassName: '' WindowName: 'Windows Live Today'
- ClassName: '' WindowName: 'Hoje'
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''
- ClassName: '' WindowName: 'Today'
- ClassName: '' WindowName: 'MSN Today'