Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Capture' = '<Полный путь к вирусу>'
- %TEMP%\59
- %TEMP%\26
- %TEMP%\52
- %TEMP%\screen.bmp
- %TEMP%\scr.jpg
- 'www.03##ren.com':80
- www.03##ren.com/process.asp?pa#############################
- www.03##ren.com/win.asp
- DNS ASK www.03##ren.com