Техническая информация
- %PROGRAM_FILES%\Internet Explorer\carss.exe "%PROGRAM_FILES%\Internet Explorer\flash.ocx" LiuliuYsMain
- %WINDIR%\regedit.exe /s C:\1.reg
- %TEMP%\144531_res.tmp
- %TEMP%\141453_res.tmp
- %PROGRAM_FILES%\Internet Explorer\carss.exe
- из %PROGRAM_FILES%\tmp.tmp в %PROGRAM_FILES%\Internet Explorer\SqlServer.exe
- из <Полный путь к вирусу> в %PROGRAM_FILES%\tmp.tmp
- 'qq####7888.vicp.cc':3660
- DNS ASK qq####7888.vicp.cc
- ClassName: 'RegEdit_RegEdit' WindowName: ''