Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'doad' = '%PROGRAM_FILES%\DoAD\doadup.exe'
- %PROGRAM_FILES%\DoAD\doadup.exe <Полный путь к вирусу>
- %PROGRAM_FILES%\DoAD\doadup.exe (загружен из сети Интернет)
- %PROGRAM_FILES%\DoAD\doadm.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\doadm[1].dll
- %PROGRAM_FILES%\DoAD\uninstall.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\inst_ok[1].asp
- %TEMP%\nsd2.tmp\nsRandom.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\doadup[1].exe
- %TEMP%\nsd2.tmp\InetLoad.dll
- %PROGRAM_FILES%\DoAD\doadup.exe
- %PROGRAM_FILES%\DoAD\doad.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\doad[1].exe
- %TEMP%\nsd2.tmp\nsRandom.dll
- %TEMP%\nsd2.tmp\InetLoad.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\inst_ok[1].asp
- 'www.do##.co.kr':80
- www.do##.co.kr/app/file/doadm.dll
- www.do##.co.kr/app/inst_ok.asp?ui################################################
- www.do##.co.kr/app/file/doadup.exe
- www.do##.co.kr/app/file/doad.exe
- DNS ASK www.do##.co.kr
- ClassName: 'Shell_TrayWnd' WindowName: ''