Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\MemoThisMonService] 'Start' = '00000002'
- %PROGRAM_FILES%\MemoThisPOP\MemoThisPOP.exe
- %PROGRAM_FILES%\MemoThisPOP\MemoThisMon.exe
- %PROGRAM_FILES%\MemoThisPOP\MemoThisMon.exe /INSTALL /SILENT
- Библиотека-обработчик для всех процессов: %PROGRAM_FILES%\MemoThisPOP\dwlgina3.dll
- %PROGRAM_FILES%\MemoThisPOP\uninstall.bat
- %PROGRAM_FILES%\MemoThisPOP\dwlGina3.dll
- %PROGRAM_FILES%\MemoThisPOP\MemoThisPOP.ini
- %PROGRAM_FILES%\MemoThisPOP\MemoThisPOP.exe
- %PROGRAM_FILES%\MemoThisPOP\MemoThisMon.exe
- из <Полный путь к вирусу> в %PROGRAM_FILES%\MemoThisPOP\<Имя вируса>.exe
- 'cl####.additcom.com':80
- 'www.ad###com.com':80
- cl####.additcom.com/updateV12/CUP_VER.html?u=########
- cl####.additcom.com/updateV12/CUP.html?u=########
- www.ad###com.com/install_memothis/?ci#########################################
- cl####.additcom.com/download/MemoThisPOP.html
- DNS ASK cl####.additcom.com
- DNS ASK www.ad###com.com
- ClassName: 'NDDEAgnt' WindowName: 'NetDDE Agent'
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''