Техническая информация
- расширений файлов
- %TEMP%\is-NN01Q.tmp\Firefox Setup.exe /S /D=%PROGRAM_FILES%\Mozilla Firefox
- %TEMP%\is-72OKU.tmp\<Имя вируса>.tmp /SL5="$40036,263576,181760,<Полный путь к вирусу>"
- %TEMP%\is-NN01Q.tmp\Firefox Setup.exe (загружен из сети Интернет)
- <SYSTEM32>\shmgrate.exe OCInstallUserConfigIE
- <SYSTEM32>\rundll32.exe advpack.dll,LaunchINFSectionEx <SYSTEM32>\ieuinit.inf,Install,,260
- <SYSTEM32>\ie4uinit.exe -hide
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoInternetIcon' = '00000001'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] 'NoInternetIcon' = '00000001'
- <SYSTEM32>\INF1.tmp
- %TEMP%\is-NN01Q.tmp\Firefox Setup.exe
- <SYSTEM32>\INF3.tmp
- <SYSTEM32>\INF2.tmp
- %TEMP%\is-NN01Q.tmp\itd_en.ini
- %TEMP%\is-NN01Q.tmp\_isetup\_RegDLL.tmp
- %TEMP%\is-72OKU.tmp\<Имя вируса>.tmp
- %TEMP%\is-NN01Q.tmp\itdownload.dll
- %TEMP%\is-NN01Q.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-NN01Q.tmp\_isetup\_RegDLL.tmp
- %TEMP%\is-NN01Q.tmp\itd_en.ini
- %TEMP%\is-72OKU.tmp\<Имя вируса>.tmp
- %TEMP%\is-NN01Q.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-NN01Q.tmp\itdownload.dll
- <SYSTEM32>\INF1.tmp
- <SYSTEM32>\INF2.tmp
- %TEMP%\is-NN01Q.tmp\Firefox Setup.exe
- <SYSTEM32>\INF3.tmp
- 'co###pack.nl':80
- co###pack.nl/FirefoxEN.exe
- DNS ASK co###pack.nl
- ClassName: 'Shell_TrayWnd' WindowName: ''