Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'userinit' = '<SYSTEM32>\userinit.exe,%WINDIR%\apppatch\dykrbog.dat,'
- <SYSTEM32>\cscript.exe
- <SYSTEM32>\winlogon.exe
- nod32.exe
- opera.exe
- netxray.exe
- nod.exe
- outpost.exe
- Ragexe.exe
- RagFree.exe
- pidgin.exe
- qip.exe
- MCAGENT.EXE
- Mir3Game.exe
- magent.exe
- maplestory.exe
- miranda32.exe
- msnmsgr.exe
- NAVAPW32.EXE
- mpftray.exe
- msn6.exe
- skype.exe
- wsm.exe
- YahooMessenger.exe
- woool.exe
- wow.exe
- ybclient.exe
- ZONEALARM.EXE
- ZZ__cd75efb816b2cc__.exe
- zapro.exe
- zlclient.exe
- spidernt.exe
- sro_client.exe
- smc.exe
- so3d.exe
- trillian.exe
- winbaram.exe
- windump.exe
- TwelveSky2.exe
- WebMoney.exe
- %WINDIR%\AppPatch\dykrbog.dat
- из <Полный путь к вирусу> в %TEMP%\CBD7.tmp
- DNS ASK no####hmatic.com
- DNS ASK www.bing.com