Техническая информация
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\rouhostsip2008[1].txt
- <Полный путь к вирусу>
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\rouhostsip2008[1].txt
- 'lm######xing.w239.dns911.cn':80
- '<IP-адрес в локальной сети>':443
- '58.#9.58.20':443
- '12#.#24.9.151':80
- lm######xing.w239.dns911.cn/rouhostsip2008.txt?si########
- 12#.#24.9.151/rouhostsip2008.txt?si########
- DNS ASK lm######xing.w239.dns911.cn
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'easyclickplus9' WindowName: 'Microsoft Internet Explorer'