Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System32' = '%PROGRAM_FILES%\Your Product/System32'
- %PROGRAM_FILES%\Your Product\System32.exe
- %TEMP%\_ir_sf7_temp_0\irsetup.exe "__IRAFN:<Полный путь к вирусу>"
- %TEMP%\_ir_sf7_temp_0\IRIMG2.JPG
- %WINDIR%\Your Product Setup Log.txt
- %PROGRAM_FILES%\Your Product\System32.exe
- %TEMP%\_ir_sf7_temp_0\irsetup.exe
- %TEMP%\_ir_sf7_temp_0\irsetup.dat
- %TEMP%\_ir_sf7_temp_0\IRIMG1.JPG
- %TEMP%\_ir_sf7_temp_0\IRIMG2.JPG
- %TEMP%\_ir_sf7_temp_0\irsetup.exe
- %TEMP%\_ir_sf7_temp_0\irsetup.dat
- %TEMP%\_ir_sf7_temp_0\IRIMG1.JPG
- 'sm##.gmail.com':25
- DNS ASK sm##.gmail.com
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''