Техническая информация
- %PROGRAM_FILES%\Internet Explorer\carss.exe "%PROGRAM_FILES%\Internet Explorer\FuckBaby.dll" rukou
- <SYSTEM32>\GroupPolicy\User\Scripts\scripts.ini
- %PROGRAM_FILES%\Internet Explorer\FuckBaby.dll
- %PROGRAM_FILES%\Internet Explorer\carss.exe
- <SYSTEM32>\GroupPolicy\gpt.ini
- из <Полный путь к вирусу> в %CommonProgramFiles%\QQ.exe
- 'wx####2.gnway.net':19820
- DNS ASK wx####2.gnway.net