Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\BITS] 'Start' = '00000002'
- %WINDIR%\6322.exe
- %WINDIR%\RapidShare Plus.exe
- %TEMP%\BIT2.tmp
- %TEMP%\BIT4.tmp
- %WINDIR%\RapidShare Plus.exe
- %WINDIR%\6322.exe
- 'ad####ideohome.net':80
- 'localhost':1039
- 'wp#d':80
- 'localhost':1037
- ad####ideohome.net/task.php?ad###############
- ad####ideohome.net/check.php
- wp#d/wpad.dat
- DNS ASK ad####ideohome.net
- DNS ASK wp#d
- ClassName: 'Shell_TrayWnd' WindowName: ''