Техническая информация
- '<SYSTEM32>\net1.exe' stop sharedaccess
- '<SYSTEM32>\net.exe' stop sharedaccess
- %PROGRAM_FILES%\b.dat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\a[1].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\CA7ESJV1.asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\a[1].asp
- %PROGRAM_FILES%\b.dat
- из <Полный путь к вирусу> в <Текущая директория>\UNINST.DAT
- 'localhost':1040
- 'ow###sezo.com':80
- 'localhost':1036
- ow###sezo.com/a.txt
- ow###sezo.com/a.asp
- DNS ASK ow###sezo.com
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'