Техническая информация
- '<SYSTEM32>\tskill.exe' taskmgr
- '<SYSTEM32>\tskill.exe' cmd
- <SYSTEM32>\cmd.exe
- <Полный путь к вирусу>
- %TEMP%\~DFC643.tmp
- 'ka####s.cafe24.com':80
- 'localhost':1038
- http://ka####s.cafe24.com/program/hosts
- DNS ASK ka####s.cafe24.com
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''