Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'svchost' = '"<Полный путь к вирусу>"'
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\1ab7fb6cc4e417da431694f8[1].html
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\qlogin[1]
- <Полный путь к вирусу>
- 'hi.##idu.com':80
- 'sm##.qq.com':25
- 'localhost':1036
- 'xu#.##login2.qq.com':80
- hi.##idu.com/kaixiaoli110/blog/item/1ab7fb6cc4e417da431694f8.html?ti#####################
- xu#.##login2.qq.com/cgi-bin/qlogin
- DNS ASK sm##.qq.com
- DNS ASK hi.##idu.com
- DNS ASK xu#.##login2.qq.com
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''