Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'eZstub' = '<Полный путь к вирусу> /Uninstall3 %PROGRAM_FILES%\eZula'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'eZstub' = '<Полный путь к вирусу>'
- %WINDIR%\eZinstall.exe (загружен из сети Интернет) /s
- %WINDIR%\eZinstall.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\UVid[1].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\UVid[1].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\eZinstall[1].exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\UVid[1].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\UVid[1].asp
- 'a9#.#.akamai.net':80
- 'www.ez##a.com':80
- www.ez##a.com/Web3K/download/UVid.asp?Pu#######################################
- a9#.#.akamai.net/f/94/1622/12h/www.ezula.com/Web3K/install/eZinstall.exe
- www.ez##a.com/Web3K/download/UVid.asp?Pu######################################
- DNS ASK a9#.#.akamai.net
- DNS ASK www.ez##a.com
- ClassName: 'eZwindow class' WindowName: 'eZStubWin'