Техническая информация
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\xxx3[1].ini
- %WINDIR%\info.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\xxx3[1].ini
- %WINDIR%\info.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\xxx3[1].ini
- %WINDIR%\info.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\xxx3[1].ini
- из <Полный путь к вирусу> в %TEMP%\123.txt
- 'we#.#77q.com':80
- 'localhost':1036
- we#.#77q.com/sms/xxx3.ini
- DNS ASK we#.#77q.com