Техническая информация
- <SYSTEM32>\cmd.exe /c ""<Текущая директория>\del.bat""
- %WINDIR%\regedit.exe /s %WINDIR%\sharedapp.reg
- <SYSTEM32>\regsvr32.exe /s "<SYSTEM32>\oobe\msobe.dll"
- <SYSTEM32>\oobe\msobcommw.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\seguro[1].js
- <SYSTEM32>\oobe\msobweb2.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\main[1].js
- <Текущая директория>\del.bat
- %WINDIR%\sharedapp.reg
- <SYSTEM32>\oobe\spoolsv.exe
- %WINDIR%\sharedappx.reg
- <SYSTEM32>\oobe\dialmgr
- C:\MSDOS.INF
- %WINDIR%\system\<Имя вируса>.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\protecao[1].js
- <SYSTEM32>\oobe\msobe.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\header[1].js
- %WINDIR%\system\<Имя вируса>.exe
- %WINDIR%\sharedapp.reg
- %WINDIR%\sharedappx.reg
- 'www.lu#####pinheiro.kit.net':80
- 'localhost':1035
- www.lu#####pinheiro.kit.net/seguro.js
- www.lu#####pinheiro.kit.net/main.js
- www.lu#####pinheiro.kit.net/header.js
- www.lu#####pinheiro.kit.net/protecao.js
- DNS ASK www.lu#####pinheiro.kit.net
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'wPrimeira' WindowName: ''