Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\wwwznv32.exe
- %WINDIR%\Explorer.EXE
- %TEMP%\~TM9.tmp
- %TEMP%\~TM8.tmp
- %TEMP%\~TM7.tmp
- %WINDIR%\Temp\~TMC.tmp
- %WINDIR%\Temp\~TMB.tmp
- %WINDIR%\Temp\~TMA.tmp
- %TEMP%\~TM5.tmp
- %TEMP%\~TM3.tmp
- %TEMP%\~TM2.tmp
- %TEMP%\~TM1.tmp
- %TEMP%\~TM4.tmp
- %TEMP%\~TM15258.TMP
- %APPDATA%\avdrn.dat
- %HOMEPATH%\Start Menu\Programs\Startup\wwwznv32.exe
- %TEMP%\~TM15258.TMP
- %TEMP%\~TM9.tmp
- %TEMP%\~TM8.tmp
- %WINDIR%\Temp\~TMC.tmp
- %WINDIR%\Temp\~TMB.tmp
- %WINDIR%\Temp\~TMA.tmp
- %TEMP%\~TM3.tmp
- %TEMP%\~TM2.tmp
- %TEMP%\~TM1.tmp
- %TEMP%\~TM7.tmp
- %TEMP%\~TM5.tmp
- %TEMP%\~TM4.tmp
- из <Полный путь к вирусу> в %TEMP%\~TM6.tmp
- 'tu##mug.ru':80
- tu##mug.ru/news/controller.php?ac##############################################################
- DNS ASK tu##mug.ru
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'