Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '<Полный путь к вирусу>'
- %HOMEPATH%\Start Menu\Programs\Startup\Win32System.dll.exe
- %HOMEPATH%\Start Menu\Programs\Startup\<Имя вируса>.exe
- 'sm##.web.de':587
- 'lo####.square7.ch':21
- 'wp#d':80
- 'www.lo####.square7.ch':80
- wp#d/wpad.dat
- www.lo####.square7.ch/CC.txt
- DNS ASK sm##.web.de
- DNS ASK lo####.square7.ch
- DNS ASK wp#d
- DNS ASK www.lo####.square7.ch
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'