Техническая информация
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\xxx[1].ini
- %WINDIR%\info.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\xxx[1].ini
- %WINDIR%\info.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\xxx[1].ini
- %WINDIR%\info.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\xxx[1].ini
- из <Полный путь к вирусу> в %TEMP%\123.txt
- 'we#.#77q.com':80
- 'localhost':1034
- we#.#77q.com/sms/xxx.ini
- DNS ASK we#.#77q.com
- '<IP-адрес в локальной сети>':1035