Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,<Полный путь к вирусу>,'
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\SL6TKFAX\img02[1].jpg
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\img03[1].jpg
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\img03[1].jpg
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\ULU3YH2D\img02[1].jpg
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\img01[1].jpg
- <SYSTEM32>tempfile.temp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\img01[1].jpg
- <SYSTEM32>tempfile.temp
- '20#.#2.75.107':80
- '70.#6.68.75':80
- 20#.#2.75.107/ind/img02.jpg
- 70.#6.68.75/primario/img03.jpg
- 20#.#2.75.107/ind/img03.jpg
- 70.#6.68.75/primario/img01.jpg
- 20#.#2.75.107/ind/img01.jpg
- 70.#6.68.75/primario/img02.jpg