Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'KB0948' = '<Полный путь к вирусу>'
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\sendcommand[1].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\ULU3YH2D\sendcommand[1].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\google[1]
- <Текущая директория>\debug.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\ULU3YH2D\sendcommand[1].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\sendcommand[1].asp
- '<IP-адрес в локальной сети>':80
- '74.##5.232.51':80
- <IP-адрес в локальной сети>/RCWServer/sendcommand.asp?DA###################################
- 74.##5.232.51/
- DNS ASK www.google.com
- ClassName: 'Indicator' WindowName: ''