Техническая информация
- [<HKLM>\SOFTWARE\Classes\Kotato.FLVPlayer.play\shell\open\command] '' = '"<Полный путь к вирусу>" "%1"'
- %TEMP%\~FP1.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\update[1].xml
- %HOMEPATH%\My Documents\My Videos\Desktop.ini
- %HOMEPATH%\My Documents\My Videos\Desktop.ini
- %TEMP%\~FP1.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\update[1].xml
- 'www.ko##to.com':80
- www.ko##to.com/youtube-downloader/update.xml
- DNS ASK www.ko##to.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'