Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Diagnostic Manager' = '<Полный путь к вирусу>'
- скрытых файлов
- расширений файлов
- Редактора реестра (RegEdit)
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFolderOptions' = '00000001'
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\sh[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\sh[1].php
- 'mi###five.info':80
- mi###five.info/ff/sh.php?ve#####
- DNS ASK mi###five.info
- ClassName: 'jks387sfij3d' WindowName: 'qw3qr98fjiokmgf0'
- ClassName: 'loto82' WindowName: 'Systems'
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'uhsf387ihjsfn3f' WindowName: 'fs3h98rw3jbnr873'
- ClassName: 'clk_gfjk' WindowName: 'clk_jdfhid'
- ClassName: 'jhsf78i3ujnkdsvc' WindowName: 'sdfcj9w83jkdmfnf'
- ClassName: 'zimbabo_rulit' WindowName: 'ugagagaga_hapulotos'
- ClassName: 'kf8wjoknfd' WindowName: 'wui3h83whjndf7'