Техническая информация
- <SYSTEM32>\regsvr32.exe <SYSTEM32>\MSWINSCK.ocx /s
- ccapp.exe
- NAVAPW32.EXE
- AVPM.EXE
- ZONEALARM.EXE
- MCAGENT.EXE
- zlclient.exe
- <SYSTEM32>\IJL10.DLL
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\IJL10[1].DLL
- <SYSTEM32>\MSWINSCK.ocx
- из <Полный путь к вирусу> в %WINDIR%\woot.exe
- 'ir#.##azenet.com':7000
- 'www.wo####ng-back.com':80
- 'localhost':1035
- www.wo####ng-back.com/DOWNLOAD/VBPROGRAMME/IJL10.DLL
- DNS ASK ir#.##azenet.com
- DNS ASK www.wo####ng-back.com
- ClassName: 'Shell_TrayWnd' WindowName: ''