Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'MSFox' = '<Полный путь к вирусу>'
- %TEMP%\~tmpa.exe
- %TEMP%\~tmpa.exe (загружен из сети Интернет)
- %TEMP%\~tmpa.exe
- '19#.#43.179.0':80
- 'pr#####ingoutlook.com':80
- '11#.#49.201.198':80
- 'be####0images.com':80
- 'im#####ig-library.com':80
- pr#####ingoutlook.com/icons/logo.gif
- 19#.#43.179.0/images/logo.gif
- 11#.#49.201.198/images/logo.gif
- DNS ASK im####-library.com
- DNS ASK pr#####ingoutlook.com
- DNS ASK pi####es-base.com
- DNS ASK be####0images.com
- DNS ASK im#####ig-library.com
- DNS ASK pi#####s-library.com
- ClassName: 'Indicator' WindowName: ''