Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows Start Services' = '<Полный путь к вирусу> /background'
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\sid[1].htm
- 'de####ty.110mb.com':80
- de####ty.110mb.com/clientes/sid.php
- DNS ASK de####ty.110mb.com
- ClassName: '' WindowName: '????? ????? ????? ?.?. - ??????? ???????'
- ClassName: '' WindowName: '?? ???????? ?????? ?????? ?? - ??????? ???????'
- ClassName: '' WindowName: '???????? - ????????? ???? - ??????? ???????'
- ClassName: '' WindowName: '????? ???? - ????? ???? ???? - ??????? ???????'