Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'coco' = '<Полный путь к вирусу>'
- '<SYSTEM32>\ipconfig.exe' /flushdns
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\dns[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\count[1].asp
- 'www.il###ller.com':80
- 'www.db##ri.com':80
- 'tj.###texist.org':80
- www.il###ller.com/mtboard/upload/kr_data/ip.txt
- www.db##ri.com/mboard/pds/qna/dns.txt
- tj.###texist.org/count.asp?ma################
- DNS ASK www.il###ller.com
- DNS ASK www.db##ri.com
- DNS ASK tj.###texist.org