Техническая информация
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\<Имя вируса>.exe
- <Имя диска съемного носителя>:\run.exe
- <Текущая директория>\taskmgr.exe
- outpost.exe
- zlclient.exe
- bdagent.exe
- AVP.EXE
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\user[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\log[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\ULU3YH2D\home[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\log[1].php
- <Текущая директория>\taskmgr.exe
- C:\readme.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\log[2].php
- <Текущая директория>\taskmgr.exe
- 'yo##ube.com':80
- 'm.###ebook.com':80
- 'localhost':1035
- '74.##5.232.51':80
- 74.##5.232.51/log.php?Ld#######################################
- m.###ebook.com/home.php?
- 74.##5.232.51/log.php?Ld################################################
- yo##ube.com/user/
- DNS ASK m.###ebook.com
- DNS ASK yo##ube.com
- DNS ASK www.google.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''