Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'Explorer.exe %WINDIR%\WindowsXP.exe'
- Диспетчера задач (Taskmgr)
- %TEMP%\ixp000.tmp\sprint.exe
- %WINDIR%\windowsxp.exe
- %WINDIR%\up4.txt
- 'su####surplus.com':80
- DNS ASK su####surplus.com
- DNS ASK so####rld.com.vn
- DNS ASK se####oid.com.br
- DNS ASK na###owice.com
- DNS ASK pr###ndng.com
- ClassName: 'OpWindow' WindowName: ''
- ClassName: 'MozillaUIWindowClass' WindowName: ''
- '%TEMP%\ixp000.tmp\sprint.exe'
- '%TEMP%\ixp000.tmp\sprint.exe' (со скрытым окном)