Техническая информация
- %PROGRAM_FILES%\Internet Explorer\carss.exe "%PROGRAM_FILES%\Internet Explorer\FuckBaby.dll" rukou
- <SYSTEM32>\GroupPolicy\gpt.ini
- <SYSTEM32>\GroupPolicy\User\Scripts\scripts.ini
- %PROGRAM_FILES%\Internet Explorer\carss.exe
- %PROGRAM_FILES%\Internet Explorer\FuckBaby.dll
- из <Полный путь к вирусу> в %WINDIR%\QQ.exe
- 'localhost':8786