Техническая информация
- <SYSTEM32>\netstat.exe файлом <SYSTEM32>\netstat.exe
- %WINDIR%\inf\Wdica.hiv
- %WINDIR%\inf\Wdica.sys
- <SYSTEM32>\ipsecstab.dat
- %WINDIR%\inf\Https.hiv
- %WINDIR%\ime\helps.txt
- %WINDIR%\inf\ws2hlp.PNF
- %WINDIR%\inf\Https.sys
- %WINDIR%\inf\Https.pnf
- %WINDIR%\inf\Https.dll
- %WINDIR%\inf\Https.pnf
- %WINDIR%\inf\Https.dll
- %WINDIR%\inf\Https.sys
- %WINDIR%\ime\helps.txt
- %WINDIR%\inf\Https.hiv
- %WINDIR%\inf\Wdica.hiv
- <SYSTEM32>\netstat.exe в <SYSTEM32>\1245
- из <Полный путь к вирусу> в %HOMEPATH%\My Documents\My Pictures\_@2.tmp
- DNS ASK 1.####.3322.org.cn
- DNS ASK 2.####.3322.org.cn
- DNS ASK te##.#322.org.cn
- '<IP-адрес в локальной сети>':1036
- ClassName: 'Shell_TrayWnd' WindowName: ''