Техническая информация
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\Sarver.url
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\cgi_get_portrait[1].fcg
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\woaiyuchangli.blog.163[1]
- <Полный путь к вирусу>
- 'ba##.#zone.qq.com':80
- 'wo######angli.blog.163.com':80
- ba##.#zone.qq.com/fcg-bin/cgi_get_portrait.fcg?ui#######################
- wo######angli.blog.163.com/
- DNS ASK ba##.#zone.qq.com
- DNS ASK wo######angli.blog.163.com