Техническая информация
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\svchost.exe
- %WINDIR%\Explorer.EXE
- [\REGISTRY\USER\SOFTWARE\Far\Plugins\FTP\Hosts]
- [<HKLM>\SOFTWARE\Far\Plugins\FTP\Hosts]
- [<HKCU>\Software\Sota\FFFTP\Options]
- [<HKCU>\SOFTWARE\Far\Plugins\FTP\Hosts]
- [<HKCU>\Software\CoffeeCup Software\Internet\Profiles]
- [\REGISTRY\USER\Software\CoffeeCup Software\Internet\Profiles]
- [<HKLM>\Software\CoffeeCup Software\Internet\Profiles]
- <SYSTEM32>\wbem\proquota.exe
- %TEMP%\~TM5.tmp
- %TEMP%\~TM6.tmp
- %TEMP%\~TM81EC3F.TMP
- %TEMP%\~TM1.tmp
- %TEMP%\~TM2.tmp
- %TEMP%\~TM3.tmp
- <SYSTEM32>\dllcache\proquota.exe
- <SYSTEM32>\proquota.exe
- %TEMP%\~TM6.tmp
- %TEMP%\~TM5.tmp
- %TEMP%\~TM2.tmp
- %TEMP%\~TM1.tmp
- %TEMP%\~TM81EC3F.TMP
- %TEMP%\~TM3.tmp
- из <Полный путь к вирусу> в %TEMP%\~TM4.tmp
- 'ii#.lc':80
- ii#.lc/css/receiver/online
- DNS ASK ii#.lc