Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,urbab.exe'
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\urbab.exe
- 'ms####.sx186.39226.cn':80
- ms####.sx186.39226.cn/pat/ms2007.bmp
- ms####.sx186.39226.cn/pat/ms2007.jpg
- ms####.sx186.39226.cn/pat/ms2007.gif
- DNS ASK ms####.sx186.39226.cn
- DNS ASK www.bl###plaync.com