Техническая информация
- Редактора реестра (RegEdit)
- '<SYSTEM32>\cmd.exe' /c <Текущая директория>\<Имя вируса>.bat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\flashplayer[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\MGJHFNSDGESGHFHGFDGHFGGHFNGGF[1].pac
- <Текущая директория>\<Имя вируса>.bat
- '20#.#8.162.21':80
- 'ge#.#dobe.com':80
- 'localhost':1039
- 'da###osa.com':80
- ge#.#dobe.com/br/flashplayer/
- 20#.#8.162.21/MGJHFNSDGESGHFHGFDGHFGGHFNGGF.pac
- da###osa.com/includes/blumenal/conta_infects.php
- DNS ASK ge#.#dobe.com
- DNS ASK da###osa.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''