Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Win32' = '<Полный путь к вирусу>'
- C:\svchos.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\ULU3YH2D\status[1].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\SL6TKFAX\status[1].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\status[2].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\status[1].asp
- <Текущая директория>\data.tmp
- C:\svchos.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\status[1].asp
- C:\svchos.exe
- <Текущая директория>\data.tmp
- 'st####.gadu-gadu.pl':80
- st####.gadu-gadu.pl/users/status.asp?id################
- DNS ASK st####.gadu-gadu.pl