Техническая информация
- '<SYSTEM32>\cmd.exe' /c Regsvr32 "%WINDIR%\xjava.dll" /s
- '<SYSTEM32>\regsvr32.exe' "%WINDIR%\xjava.dll" /s
- '<SYSTEM32>\cmd.exe' /c Regsvr32 "%WINDIR%\syspflash.dll" /s
- '<SYSTEM32>\regsvr32.exe' "%WINDIR%\syspflash.dll" /s
- %WINDIR%\xjava.dll
- %WINDIR%\syspflash.dll
- <Полный путь к вирусу>
- 'sm###.uol.com.br':25
- 'wi#######y2.win5.f1.k8.com.br':80
- 'localhost':1037
- http://wi#######y2.win5.f1.k8.com.br/hot.jpg
- http://wi#######y2.win5.f1.k8.com.br/2caras.jpg
- DNS ASK sm###.uol.com.br
- DNS ASK wi#######y2.win5.f1.k8.com.br
- ClassName: 'Shell_TrayWnd' WindowName: ''