Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup1\TM.lnk
- '%PROGRAM_FILES%\snss.exe'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\123.bat" "
- '<SYSTEM32>\regsvr32.exe' /s "<SYSTEM32>\Thunder.dll"
- %PROGRAM_FILES%\Internet Explorer\<Имя вируса>.exe
- C:\1.lnk
- %TEMP%\123.txt
- C:\2.lnk
- <SYSTEM32>\Thunder.dll
- <SYSTEM32>\sysini.ini
- <SYSTEM32>\csys.dat
- %PROGRAM_FILES%\snss.exe
- %TEMP%\~DF13DA.tmp
- C:\2.lnk
- C:\1.lnk
- %TEMP%\123.txt в %TEMP%\123.bat
- 'tj.##8988.com':80
- 'localhost':1035
- DNS ASK tj.##8988.com