Техническая информация
- %PROGRAM_FILES%\ThunderLiveUD.exe
- <SYSTEM32>\rundll32.exe shimgvw.dll,ImageView_Fullscreen %TEMP%\121875.jpg
- <Полный путь к вирусу>
- %TEMP%\spuninst.rar
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\spuninst[1].rar
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\updspapi[1].rar
- %PROGRAM_FILES%\fTђGћNbc\niudll.jpg
- %TEMP%\updspapi.rar
- %WINDIR%\vbcfg.ini
- %PROGRAM_FILES%\ThunderLiveUD.exe
- %TEMP%\nsh2.tmp
- %TEMP%\nsb3.tmp\System.dll
- <SYSTEM32>\aFs5QE.pic
- %TEMP%\121875.jpg
- %TEMP%\nsb3.tmp\System.dll
- %TEMP%\updspapi.rar в %PROGRAM_FILES%\fTђGћNbc\update\updspapi.dll
- %TEMP%\spuninst.rar в %PROGRAM_FILES%\fTђGћNbc\spuninst.exe
- 'wo##.vicp.hk':80
- 'localhost':1035
- wo##.vicp.hk/updspapi.rar
- wo##.vicp.hk/spuninst.rar
- DNS ASK wo##.vicp.hk
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'ShImgVw:CPreviewWnd' WindowName: ''