Техническая информация
- Редактора реестра (RegEdit)
- <SYSTEM32>\cmd.exe /c <Текущая директория>\<Имя вируса>.bat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\flashplayer[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\MFGJHDDFHRJERWEJSJSDDSHDSNREJFEHGFDFHSDAKAKKJFDCNDJJ[1].pac
- <Текущая директория>\<Имя вируса>.bat
- '20#.#8.149.66':80
- 'ge#.#dobe.com':80
- 'localhost':1037
- 'da###osa.com':80
- ge#.#dobe.com/br/flashplayer/
- 20#.#8.149.66/MFGJHDDFHRJERWEJSJSDDSHDSNREJFEHGFDFHSDAKAKKJFDCNDJJ.pac
- da###osa.com/includes/arena-infect/conta_infects.php
- DNS ASK ge#.#dobe.com
- DNS ASK da###osa.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''