Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'sys' = '%WINDIR%\wan.exe'
- %PROGRAM_FILES%\MP3 Bot\mp3bot.exe
- MCAGENT.EXE
- %HOMEPATH%\Desktop\MP3 Bot.lnk
- %PROGRAM_FILES%\MP3 Bot\mp3bot.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\state[1].aspx
- %WINDIR%\wan.exe
- %PROGRAM_FILES%\MP3 Bot\wan.exe
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\2.tmp
- %PROGRAM_FILES%\MP3 Bot\MSINET.OCX
- %PROGRAM_FILES%\MP3 Bot\msflxgrd.ocx
- %PROGRAM_FILES%\MP3 Bot\MSCOMCTL.OCX
- %TEMP%\$inst\temp_0.tmp
- 'www.mp####scador.com':80
- 'localhost':1035
- www.mp####scador.com/_xml//state.aspx
- DNS ASK www.mp####scador.com
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''