Техническая информация
- '%WINDIR%\security\<Имя вируса>.exe'
- '<SYSTEM32>\ping.exe' localhost
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\1444A.cmd
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\l[1].exe
- %WINDIR%\security\1-9.exe
- %WINDIR%\security\<Имя вируса>.exe
- %WINDIR%\1444A.cmd
- 'li##.ath.cx':80
- li##.ath.cx/l.exe
- DNS ASK li##.ath.cx