Техническая информация
- '<SYSTEM32>\regsvr32.exe' <SYSTEM32>\MSWINSCK.ocx /s
- AVPM.EXE
- NAVAPW32.EXE
- ZONEALARM.EXE
- <SYSTEM32>\IJL10.DLL
- %WINDIR%\niggapoops.exe
- <SYSTEM32>\MSWINSCK.ocx
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\IJL10[1].DLL
- из <Полный путь к вирусу> в %WINDIR%\woot.exe
- 'lo###.oscar.aol.com':5190
- 'www.wo####ng-back.com':80
- 'localhost':1036
- www.wo####ng-back.com/DOWNLOAD/VBPROGRAMME/IJL10.DLL
- DNS ASK lo###.oscar.aol.com
- DNS ASK www.wo####ng-back.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'