Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\MakeFortune Service] 'Start' = '00000002'
- '%PROGRAM_FILES%\MakeFortune\MakeFortune Service.exe' -install
- '%PROGRAM_FILES%\MakeFortune\MakeFortune.exe' Service.exe
- '%PROGRAM_FILES%\MakeFortune\MakeFortune.exe'
- '%PROGRAM_FILES%\MakeFortune\MakeFortune.exe' -u=http://12#.##.67.230:8080/test.txt
- %PROGRAM_FILES%\MakeFortune\MakeFortune Service.exe
- %PROGRAM_FILES%\MakeFortune\MakeFortune.exe
- из <Полный путь к вирусу> в %TEMP%\_@1.tmp
- '12#.#7.67.230':8080
- 'localhost':1038
- ClassName: 'TrayNotifyWnd' WindowName: ''
- ClassName: 'Syspager' WindowName: ''
- ClassName: 'ToolbarWindow32' WindowName: ''
- ClassName: 'BDMSusFrame' WindowName: 'SusWnd'
- ClassName: 'BDMTips' WindowName: 'BDMTrayTipWnd'
- ClassName: 'Shell_TrayWnd' WindowName: ''