Техническая информация
- <SYSTEM32>\Win Types\Win Const.exe "<Полный путь к вирусу>"
- Библиотека-обработчик для всех процессов: <SYSTEM32>\Win Types\Win Const5.dll
- <SYSTEM32>\Win Types\Win Const0.idx
- <SYSTEM32>\Win Types\Win Const5.dll
- <SYSTEM32>\Win Types\Win Const.dat
- <SYSTEM32>\Win Types\1\0.dll
- %WINDIR%\1.mzp
- <SYSTEM32>\Win Types\1.mzp
- <SYSTEM32>\Win Types\Win Const.exe
- <SYSTEM32>\Win Types\Win Const.dat
- %WINDIR%\1.mzp
- '66.##1.46.139':85
- 'www.fw#.##tfirms.com':80
- 'we#.icq.com':80
- www.fw#.##tfirms.com/log.txt
- DNS ASK www.fw#.##tfirms.com
- DNS ASK we#.icq.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''