Техническая информация
- <SYSTEM32>\taskkill.exe /F /IM <Полный путь к вирусу>
- <SYSTEM32>\cmd.exe /c ""%TEMP%\xlQZx.bat" "
- %TEMP%\1A7E3.dmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\%D1%81n%D1%88%D1%84%D1%83%C2%B5s-kubilius-%D0%AA0%E2%80%998-%D1%94%C2%BB-%C2%AE6%D1%8A1%E2%80%9E-%C2%B03-2%D2%91jpg&%D1%8C=640&%D1%84=%E2%80%9A0%C2%AC&ei=[1]
- %TEMP%\xlQZx.bat
- %TEMP%\dw.log
- <Полный путь к вирусу>
- 'www.go###????.lt':80
- 'localhost':1035
- DNS ASK www.go##цзlt
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''