Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'userinit' = '<SYSTEM32>\userinit.exe,<Полный путь к вирусу>,'
- %TEMP%\tmp3D9.tmp
- %TEMP%\tmpDC2D.tmp
- %TEMP%\tmpA6D5.tmp
- %TEMP%\tmp21B2.tmp
- %TEMP%\tmp7FB0.tmp
- %TEMP%\tmp709D.tmp
- %TEMP%\tmp5499.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\index[1].php
- %TEMP%\2408.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\index[1].php
- %TEMP%\549E.tmp
- %TEMP%\tmp93AB.tmp
- %TEMP%\tmp7565.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\index[1].php
- %TEMP%\tmp21B2.tmp
- %TEMP%\tmp3D9.tmp
- %TEMP%\tmp5499.tmp
- %TEMP%\tmp7FB0.tmp
- %TEMP%\tmp709D.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\index[1].php
- %TEMP%\tmp7565.tmp
- %TEMP%\tmp93AB.tmp
- %TEMP%\tmpDC2D.tmp
- %TEMP%\tmpA6D5.tmp
- '46.##.165.110':80
- 'localhost':1035
- 46.##.165.110/rd/index.php?id################