Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'svchost' = '%APPDATA%\Microsoft\svchost.exe'
- '<SYSTEM32>\cmd.exe' /c del <Полный путь к вирусу> >> NUL
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\header[1].png
- %APPDATA%\Microsoft\svchost.exe
- 'hu####jadgert.org':80
- 'ya###ahu.com':80
- 'go##ess.net':80
- http://hu####jadgert.org/images/header.png
- http://ya###ahu.com/images/header.png
- http://go##ess.net/images/header.png
- DNS ASK hu####jadgert.org
- DNS ASK ya###ahu.com
- DNS ASK go##ess.net
- ClassName: 'Indicator' WindowName: ''