Техническая информация
- [<HKLM>\SOFTWARE\Classes\School Bankin???.Document\shell\open\command] '' = '<Полный путь к вирусу> "%1"'
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\School[1].htm
- 'ft#.##51j.com.cn':80
- 'localhost':1036
- ft#.##51j.com.cn/School.htm
- DNS ASK ft#.##51j.com.cn
- '<IP-адрес в локальной сети>':1037
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''