Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'shell' = 'explorer.exe,<Полный путь к вирусу>'
- '<SYSTEM32>\regsvr32.exe' /s "%ALLUSERSPROFILE%\Application Data\Microsoft\Media Player\wmpns.dll"
- %ALLUSERSPROFILE%\Application Data\Microsoft\Media Player\wmpns.dll
- 'www.dh###ufnb.com':80
- 'localhost':1037
- www.dh###ufnb.com/www.txt
- DNS ASK www.dh###ufnb.com