Техническая информация
- '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE' http://www.5s##a.cn/Camfrog/1.htm
- '<SYSTEM32>\mshta.exe' vbscript:createobject("wscript.shell").run("""<Имя вируса>.exe"" h",0)(window.close)
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\1[1].htm
- %TEMP%\~2.bat
- %TEMP%\~1.bat
- %TEMP%\~2.bat
- %TEMP%\~1.bat
- %TEMP%\~1.bat
- 'www.5s##a.cn':80
- 'localhost':1035
- www.5s##a.cn/Camfrog/1.htm
- DNS ASK www.5s##a.cn
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: '' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'