Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\WinboX87.exe
- '%HOMEPATH%\Start Menu\Programs\Startup\WinboX87.exe'
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -nohome
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\CONTAINFECTTTTTTTT[1]
- %TEMP%\~DF18E6.tmp
- %TEMP%\~DF97A7.tmp
- %TEMP%\~DF18E6.tmp
- 't#.##tatuba.om':21
- 'bi#.ly':80
- 'localhost':1036
- http://bi#.ly/CONTAINFECTTTTTTTT
- DNS ASK t#.##tatuba.om
- DNS ASK bi#.ly
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''