Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'BD' = '"%TEMP%\dc.exe"'
- %TEMP%\dc.exe
- %PROGRAM_FILES%\Outlook Express\fa2.exe
- %TEMP%\dc.exe
- %TEMP%\backdoor.log
- %PROGRAM_FILES%\Outlook Express\fa2.exe
- 'ho####.thebbs.org':9123
- DNS ASK ho####.thebbs.org
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''