Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'coco' = '<Полный путь к вирусу>'
- '<SYSTEM32>\ipconfig.exe' /flushdns
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\dns[1].txt
- '11#.#13.124.168':555
- 'www.db##ri.com':80
- 'yj#.###an-engineer.com':66
- www.db##ri.com/mboard/pds/qna/dns.txt
- DNS ASK www.db##ri.com
- DNS ASK yj#.###an-engineer.com