Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '360SAVETASK' = '<SYSTEM32>\360SaveTask.exe'
- '<SYSTEM32>\360SaveTask.exe'
- '<SYSTEM32>\cmd.exe' /c del "<Полный путь к вирусу>"
- <SYSTEM32>\usb.dat
- <SYSTEM32>\360SaveTask.exe
- 'localhost':1040
- '12#.#25.114.144':80
- 'u.###255.com':80
- '40.##6688.com':80
- http://www.ba##u.com/ via 12#.#25.114.144
- http://40.##6688.com/555.asp?ma###############################
- http://u.###255.com/image/ym.jpg
- DNS ASK www.ba##u.com
- DNS ASK 40.##6688.com
- DNS ASK u.###255.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell DocObject View' WindowName: ''
- ClassName: 'Internet Explorer_Server' WindowName: ''