Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] 'tj' = 'tj:*:Enabled:<Полный путь к вирусу>'
- <Текущая директория>\umbrella.exe /hiderun
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\wbhp[1].shtml
- <Текущая директория>\umbrella.exe
- <SYSTEM32>\csrsrw.dll
- <Текущая директория>\umbrella.exe
- 'www.so##.com':80
- 'localhost':1039
- 'da##.#2taojin.com':80
- www.so##.com/wbhp.shtml?un############
- da##.#2taojin.com/api/19110.xml
- DNS ASK www.so##.com
- DNS ASK da##.#2taojin.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Progman' WindowName: 'Program Manager'
- ClassName: 'SHELLDLL_DefView' WindowName: ''
- ClassName: 'SysListView32' WindowName: 'FolderView'