Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Windows Session Manager Subsystem' = '<Текущая директория>\smss.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Windows Logon Process' = '<Текущая директория>\winlogon.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'IE Redir' = '<Полный путь к вирусу>'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WinSysModule' = 'dsrss.exe'
- <SYSTEM32>\sc.exe delete mctskshd.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\softlinkdata[1].inc
- %WINDIR%\httpconf.dat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\adminclients[1].html
- <SYSTEM32>\drv32dta\pstore_121023_004420.txt
- <SYSTEM32>\drv32dta\cookies_121023_004420.txt
- 'sh######atyouvegotto.biz':80
- 'localhost':1038
- '20#.#6.232.182':80
- sh######atyouvegotto.biz/admin/admin//clients/adminclients.html
- sh######atyouvegotto.biz/admin/admin//clients/softlinkdata.inc
- DNS ASK sh######atyouvegotto.biz
- DNS ASK www.microsoft.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''