Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Smgp' = '<Полный путь к вирусу>'
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\УСЗйМбКѕI.lnk
- <SYSTEM32>\BlackList.ini
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\УСЗйМбКѕII.lnk
- %HOMEPATH%\Desktop\»бФ±Иє·ў.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\ј±єфАП°е.lnk
- <SYSTEM32>\Smgp.dll
- <SYSTEM32>\Smgp.ini
- <SYSTEM32>\Coolrun.dll
- <Текущая директория>\SmgpBJ.exe
- <SYSTEM32>\WBSmgp.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\WBSmgp[1].dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\SmgpBJ[1].exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\BlackList[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\GetSmgpini[1].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\Smgp[1].dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\Coolrun[1].dll
- '21#.#53.33.67':80
- 'localhost':1037
- 21#.#53.33.67/Download/WBSmgp.dll
- 21#.#53.33.67/Download/SmgpBJ.exe
- 21#.#53.33.67/Download/BlackList.txt
- 21#.#53.33.67/GetSmgpini.asp
- 21#.#53.33.67/Download/Smgp.dll
- 21#.#53.33.67/Download/Coolrun.dll
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''