Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 's9201' = '"<Полный путь к вирусу>" /autorun'
- [<HKCU>\Software\Microsoft\MessengerService]
- %ALLUSERSPROFILE%\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG\20120521113026718.log
- 'in#.##pexrept.com':80
- in#.##pexrept.com/stat.php?fu########################################
- DNS ASK in#.##pexrept.com
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'msctls_updown32' WindowName: ''
- ClassName: 'TMainForm' WindowName: 'WinSpywareProtect'
- ClassName: 'Shell_TrayWnd' WindowName: ''