Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'V3QuaVwE' = '%PROGRAM_FILES%\Windows NT\Accessories\V3Data\V3QuaVwe.exe'
- '%PROGRAM_FILES%\Windows NT\Accessories\V3Data\V3QuaVwe.exe' "<Полный путь к вирусу>"
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\profilecfg[1].php
- %PROGRAM_FILES%\Windows NT\Accessories\V3Data\V3QuaVwe.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\profilecfg[1].php
- 'mo###.yesirzz.com':80
- mo###.yesirzz.com/config/profilecfg.php
- DNS ASK mo###.yesirzz.com