Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'sbthost' = '%APPDATA%\<Имя вируса>.exe'
- opera.exe
- firefox.exe
- iexplore.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\clientes[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\pacfig[1].txt
- 'se####oseguro.com':80
- 'www.to##rade.cz':80
- se####oseguro.com/clientes.php?da############################
- www.to##rade.cz/pacfig.txt
- DNS ASK us#####s.multimania.es
- DNS ASK se####oseguro.com
- DNS ASK www.to##rade.cz
- ClassName: 'Indicator' WindowName: ''