Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'common' = '%CommonProgramFiles%\<Имя вируса>.exe'
- '%CommonProgramFiles%\<Имя вируса>.exe' <Полный путь к вирусу>
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\unique-display[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\unique-display[1]
- %CommonProgramFiles%\<Имя вируса>.exe
- C:\mm.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\unique-display[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\unique-display[1]
- 'mi######orren.wordpress.com':80
- mi######orren.wordpress.com/2012/07/20/unique-display/
- DNS ASK mi######orren.wordpress.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'