Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\Internet Explorer .lnk
- %APPDATA%\Adobe\svhost.exe
- <SYSTEM32>\cmd.exe /c "%TEMP%\reload.bat"
- %TEMP%\reload.bat
- <Текущая директория>\<Имя вируса>.doc
- %APPDATA%\Adobe\svhost.exe
- 'he##.###mailerservices.com':53
- 'we#####.intarnetservice.com':80
- we#####.intarnetservice.com/AgAAAAgAAAAAAAAAAAAAAMjAxMSA4MiRxMTE2NDgzMRVTRVJtNAJCcDkBeQNwMgA
- we#####.intarnetservice.com/AgAAAAgAAAAAAAAAAAAAAMjAxMSA4MiRxMTE2NDc0OBVTRVJtNAJCcDkBeQNwMgA
- DNS ASK he##.###mailerservices.com
- DNS ASK we#####.intarnetservice.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'WordPadClass' WindowName: ''