Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\RasAuto] 'Start' = '00000002'
- '%TEMP%\Del1.tmp' 48 "<Полный путь к вирусу>"
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\DOPCG3SI\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\MMSTHW0N\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\X6AKIZMR\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\MRR3MXVO\desktop.ini
- %TEMP%\Del1.tmp
- <SYSTEM32>\rasaut.dll
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\MMSTHW0N\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\X6AKIZMR\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\MRR3MXVO\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\DOPCG3SI\desktop.ini
- '12#.###.128.128.128.128':8080
- 'pa###.spdns.de':443
- DNS ASK 12#.###.128.128.128.128
- DNS ASK pa###.spdns.de