Техническая информация
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -nohome
- iexplore.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\forum[1]
- из <Полный путь к вирусу> в <Текущая директория>\K3EFB3948J96UDQGLY73.exe
- 'www.rl###kers.net':80
- 'au##.#earch.msn.com':80
- 'localhost':1042
- 'bl###fsport.com':80
- 'localhost':1040
- http://www.rl###kers.net/forum
- http://au##.#earch.msn.com/response.asp?MT###########################
- http://bl###fsport.com/gaz/htaccess.php?n2#####
- http://bl###fsport.com/gaz/f_uck.txt?nL#####
- http://bl###fsport.com/gaz/list.txt?n9####
- DNS ASK au##.#earch.msn.com
- DNS ASK www.rl###kers.net
- DNS ASK bl###fsport.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''