Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '' = ''
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '<Имя вируса>' = '<Полный путь к вирусу>'
- %HOMEPATH%\Start Menu\Programs\System Security\System Security 2009.lnk
- %HOMEPATH%\Start Menu\Programs\System Security\System Security 2009 Support.lnk
- %HOMEPATH%\Desktop\System Security 2009.lnk
- %TEMP%\aza7B45.tmp
- %TEMP%\izohore.bmp
- %TEMP%\aza7B45.tmp
- 'zp####tqqwkw.net':80
- zp####tqqwkw.net/in.php?ur###############
- DNS ASK zp####tqqwkw.net
- '<IP-адрес в локальной сети>':1035
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'ThisIsPayFormClass' WindowName: ''