Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'sbthost' = '%APPDATA%\<Имя вируса>.exe'
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\iload[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\up[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\pacfig[1].pac
- 'me#####.multimania.nl':80
- 'us#####s.multimania.es':80
- us#####s.multimania.es/elefante6/up.txt
- us#####s.multimania.es/elefante7/up.txt
- us#####s.multimania.es/elefante8/pacfig.pac
- me#####.multimania.nl/elefante1/iload.php?da####################################
- DNS ASK me#####.multimania.nl
- DNS ASK us#####s.multimania.es
- ClassName: 'Indicator' WindowName: ''