Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\Windows Message.lnk
- '%PROGRAM_FILES%\Windows NT\Accessories\Microsoft\services.exe' "<Полный путь к вирусу>"
- '<SYSTEM32>\ipconfig.exe' /all
- %TEMP%\ms.log
- %PROGRAM_FILES%\Windows NT\Accessories\Microsoft\services.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\skywood[1].htm
- %TEMP%\ms.log
- 'we#.##rsignlist.com':80
- 'www.ha###okchon.com':80
- we#.##rsignlist.com/css/skywood.htm
- www.ha###okchon.com/css/info.gif
- DNS ASK we#.##rsignlist.com
- DNS ASK www.ha###okchon.com