Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'ezula' = '<Полный путь к вирусу> /Uninstall3 %PROGRAM_FILES%\eZula'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'ezula' = '<Полный путь к вирусу>'
- %WINDIR%\eZulains.exe /s
- %WINDIR%\eZulains.exe (загружен из сети Интернет)
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\UVid[1].asp
- %WINDIR%\eZulains.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\eZulains[1].exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\UVid[1].asp
- 'www.ez##a.com':80
- 'a9#.#.akamai.net':80
- www.ez##a.com/KaZaA/download/UVid.asp?Pu#######################################
- a9#.#.akamai.net/f/94/1622/12h/www.ezula.com/KaZaA/install/eZulains.exe
- DNS ASK www.ez##a.com
- DNS ASK a9#.#.akamai.net
- ClassName: 'eZwindow class' WindowName: 'eZStubWin'