Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '360saft' = '%PROGRAM_FILES%\Internet Explorer\iexplre.exe'
- ClassName: 'TXGuiFoundation' WindowName: 'QQ2010'
- ClassName: '' WindowName: 'QQ.exe'
- ClassName: 'TXGuiFoundation' WindowName: 'QQ2011'
- ClassName: 'TXGuiFoundation' WindowName: 'QQ2012'
- %TEMP%\1e694.tmp
- %TEMP%\1cf71.tmp
- %TEMP%\1a8fc.tmp
- %TEMP%\1e694.tmp
- %TEMP%\1cf71.tmp
- %TEMP%\1a8fc.tmp
- из <Полный путь к вирусу> в %PROGRAM_FILES%\Internet Explorer\iexplre.exe
- 'oo#.#5free.net':80
- oo#.#5free.net/hmxzdz.htm
- oo#.#5free.net/yes.no.htm
- DNS ASK oo#.#5free.net
- ClassName: 'Shell_TrayWnd' WindowName: ''