Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'MSFox' = '<Полный путь к вирусу>'
- %TEMP%\~tmpa.exe
- %TEMP%\~tmpa.exe (загружен из сети Интернет)
- %TEMP%\~tmpa.exe
- '19#.#43.179.7':80
- 'er###-pict.com':80
- 'im#####ig-library.com':80
- '11#.#49.201.199':80
- er###-pict.com/icons/logo.gif
- 19#.#43.179.7/images/logo.gif
- 11#.#49.201.199/images/logo.gif
- DNS ASK er###-pict.com
- DNS ASK pi####esbase.com
- DNS ASK pi####es-base.com
- DNS ASK im#####ig-library.com
- DNS ASK pi#####s-library.com
- DNS ASK im####-library.com
- ClassName: 'Indicator' WindowName: ''