Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunServices] 'Image' = 'rundll32 <Полный путь к вирусу>,Install'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Image' = 'rundll32 <Полный путь к вирусу>,Install'
- %WINDIR%\ieij\dict.dat
- %WINDIR%\ieij\keywords.dat
- %WINDIR%\mshp.dll
- %WINDIR%\ieij\ieij.dll
- %WINDIR%\ieij\msiesh.dll
- %WINDIR%\ieij\mssearch.dll
- 'ie###dsl.com':80
- ie###dsl.com/feat/keywords.dat
- ie###dsl.com/feat/dict.dat
- ie###dsl.com/feat/b00000.txt
- ie###dsl.com/feat/mshp.dll
- ie###dsl.com/feat/iefeatsl.dll
- ie###dsl.com/feat/update.txt
- ie###dsl.com/feat/mssearch.dll
- ie###dsl.com/feat/msiesh.dll
- DNS ASK ie###dsl.com
- ClassName: 'Indicator' WindowName: ''