Техническая информация
- <SYSTEM32>\ping.exe 127.0.0.1
- <SYSTEM32>\services.exe
- <SYSTEM32>\rundll32.exe <SYSTEM32>\shimgvw.dll,ImageView_Fullscreen <Текущая директория>\<Имя вируса>.jpg
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1804' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'WarnOnZoneCrossing' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1607' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1809' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1609' = '00000000'
- %HOMEPATH%\Recent\af32d3b0.lnk
- %HOMEPATH%\Recent\<Имя вируса>.lnk
- <SYSTEM32>\g1.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\user[1].asp
- %HOMEPATH%\My Documents\taobao\s.exe
- %HOMEPATH%\My Documents\taobao\web.exe
- <Текущая директория>\<Имя вируса>.jpg
- %TEMP%\~DFE49F.tmp
- 'www.wo####ongfeng.co.cc':80
- 'localhost':1036
- www.wo####ongfeng.co.cc/user.asp?us##############
- DNS ASK www.wo####ongfeng.co.cc
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'ShImgVw:CPreviewWnd' WindowName: ''