Техническая информация
- [<HKLM>\SOFTWARE\Classes\GoD\shell\open\command] '' = '"<Полный путь к вирусу>" /link:"%1"'
- ClassName: 'TDeDeMainForm' WindowName: ''
- ClassName: 'TIdaWindow' WindowName: ''
- ClassName: 'APIMonitor By Rohitab' WindowName: ''
- ClassName: 'RegmonClass' WindowName: ''
- ClassName: 'FilemonClass' WindowName: ''
- <Текущая директория>\ServerList.cfg
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\clientversion[1].cfg
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\ULU3YH2D\serverlist[1].cfg
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\advert[1]
- <Текущая директория>\Config.cfg
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\serverlist[1].cfg
- <Текущая директория>\ServerList2.cfg
- <Текущая директория>\ServerList.cfg
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\serverlist[1].cfg
- <Текущая директория>\ServerList2.cfg
- 'localhost':1038
- 'go##2p.pl':80
- go##2p.pl/program/info/clientversion.cfg
- go##2p.pl/advert
- go##2p.pl/program/info/serverlist.cfg
- DNS ASK go##2p.pl
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'SuckMe&Class' WindowName: ''