Техническая информация
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\xxx[1].ini
- %WINDIR%\info.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\xxx[1].ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\xxx[1].ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\xxx[1].ini
- %WINDIR%\info.ini
- из <Полный путь к вирусу> в %TEMP%\123.txt
- 'we#.#77q.com':80
- 'localhost':1036
- we#.#77q.com/sms/xxx.ini
- DNS ASK we#.#77q.com