Техническая информация
- [<HKLM>\SOFTWARE\Classes\Tomabo.MP4Player.play\shell\open\command] '' = '"<Полный путь к вирусу>" "%1"'
- %TEMP%\~MP1.tmp
- %HOMEPATH%\My Documents\My Videos\Desktop.ini
- %HOMEPATH%\My Documents\My Videos\Desktop.ini
- %TEMP%\~MP1.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\update[1].xml
- 'www.to##bo.com':80
- www.to##bo.com/youtube-video-downloader-pro/update.xml
- DNS ASK www.to##bo.com
- ClassName: 'Shell_TrayWnd' WindowName: ''