Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%PROGRAM_FILES%\Internet Explorer\Svchost.exe'
- Библиотека-обработчик для всех процессов: %PROGRAM_FILES%\Internet Explorer\HMMAPIL.DLL
- %PROGRAM_FILES%\lprvc.txt
- <SYSTEM32>\system.cfg
- %PROGRAM_FILES%\.TXT
- %PROGRAM_FILES%\Internet Explorer\obj.bin
- %PROGRAM_FILES%\Internet Explorer\_tmp.txt
- %PROGRAM_FILES%\Internet Explorer\cfg.bin
- %PROGRAM_FILES%\Internet Explorer\obj.txt
- <Полный путь к вирусу>
- %PROGRAM_FILES%\Internet Explorer\cfg.bin
- %PROGRAM_FILES%\Internet Explorer\obj.bin
- %PROGRAM_FILES%\Internet Explorer\HMMAPIL.DLL
- %PROGRAM_FILES%\Internet Explorer\Svchost.exe
- %PROGRAM_FILES%\.TXT
- %PROGRAM_FILES%\lprvc.txt
- %PROGRAM_FILES%\Internet Explorer\_tmp.txt
- 'www.ai##k.com':80
- www.ai##k.com/down.txt
- DNS ASK www.ai##k.com
- '<IP-адрес в локальной сети>':1035