Техническая информация
- [<HKLM>\SOFTWARE\Classes\SuperPad.Document.4\shell\open\command] '' = '<Полный путь к вирусу> /dde'
- 'localhost':1040
- 'www.cs##r.com':80
- 'cs###.uhostall.com':80
- www.cs##r.com/
- www.cs##r.com/csoxr.key
- cs###.uhostall.com/csoxr.key
- DNS ASK www.cs##r.com
- DNS ASK cs###.uhostall.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''