Техническая информация
- <Полный путь к вирусу>
- <DRIVERS>\mmreader.sys
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\reseller[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\logo[1].php
- %TEMP%\helper.dll
- %TEMP%\patch.dll
- %TEMP%\zqsq.dll
- '22#.4.13.71':80
- 'localhost':1040
- '12#.#25.114.144':80
- 22#.4.13.71/reseller.php
- 22#.4.13.71/logo.php
- 12#.#25.114.144/new/1819774887
- 22#.4.13.71/zqsq.php
- DNS ASK us##.#zone.qq.com
- DNS ASK hi.##idu.com
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'STATIC' WindowName: '00000AE0_PID_FastMM'
- ClassName: 'STATIC' WindowName: '00000AE0_PID_FastMM_BE'