Техническая информация
- <SYSTEM32>\regsvr32.exe /s "%TEMP%\~DFA3842.tmp"
- <SYSTEM32>\regsvr32.exe /s "%TEMP%\~DFA2708.tmp"
- <SYSTEM32>\regsvr32.exe /s "<SYSTEM32>\mswinsck.ocx"
- %TEMP%\DFA444.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\file[1].txt
- %TEMP%\4668.dat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\<Имя вируса>[1].ini
- %WINDIR%\sys.dat
- %TEMP%\~DFA2708.tmp
- <SYSTEM32>\mswinsck.ocx
- %TEMP%\4668.dat
- 'us##.yswm.net':80
- 'www.pc##8.net':80
- 'localhost':1035
- us##.yswm.net/yswm/<Служебное имя>.ini
- www.pc##8.net/file.txt
- DNS ASK us##.yswm.net
- DNS ASK www.pc##8.net