Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\BITS] 'Start' = '00000002'
- <Полный путь к вирусу> в %TEMP%\{000e9930}
- 'li###ool.info':80
- 'li###ool.net':80
- 'ri##h.net':80
- 'dy#.com':80
- 'wp#d':80
- 'localhost':1039
- http://11#.#11.111.2/wpad.dat via wp#d
- http://ri##h.net/rp/
- DNS ASK li###ool.net
- DNS ASK ri##h.net
- DNS ASK li###ool.info
- DNS ASK dy#.com
- DNS ASK wp#d