Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '"%PROGRAM_FILES%\fgnvm\obpqaef.exe"'
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://tc.#22.cc/
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.77##h.com/?88
- <SYSTEM32>\services.exe <Имя вируса>.exe
- <SYSTEM32>\svchost.exe -k netsvcs
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\PARTN[1]
- %APPDATA%\skin.ini
- %TEMP%\PARTN
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\ULU3YH2D\779dh[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\tc.v22[1]
- <SYSTEM32>\music.ico
- %TEMP%\zs.bat
- %TEMP%\lnk.bat
- <SYSTEM32>\tbhdz.ico
- %APPDATA%\Mozilla\Firefox\Profiles\przhlnon.default\prefs.js
- 'localhost':1040
- 'tc.#22.cc':80
- 'www.77##h.com':80
- 'localhost':1037
- 'do####ad.youbak.com':80
- 'localhost':1039
- www.77##h.com/?88
- tc.#22.cc/
- do####ad.youbak.com/msn/software/partner/PARTN
- DNS ASK www.77##h.com
- DNS ASK tc.#22.cc
- DNS ASK do####ad.youbak.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''