Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'mnbv' = '<Полный путь к вирусу>'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'mnbv' = '<Полный путь к вирусу>'
- ClassName: 'gdkWindowToplevel' WindowName: 'The Ethereal Network Analyzer'
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\proc[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\proc[1].php
- %WINDIR%\311d127205.imb
- 'www.fo###18073.com':80
- 'www.da##.net':80
- www.fo###18073.com/bin/update.php?ke##############
- www.fo###18073.com/log/proc.php?mo#####################
- www.da##.net/
- DNS ASK www.fo###18073.com
- DNS ASK www.da##.net
- ClassName: 'SmartSniff' WindowName: ''
- ClassName: 'PacketSnifferClass1' WindowName: ''
- ClassName: 'gdkWindowTemp' WindowName: 'wireshark.exe'
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: 'secret.txt - ??????'