Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,hurct.exe'
- '%PROGRAM_FILES%\Microsoft\MSFuckerBot.exe'
- '%PROGRAM_FILES%\MSFuckerBot1.0.exe'
- '%TEMP%\bs.exe'
- %WINDIR%\Explorer.EXE
- [<HKCU>\Software\Yahoo\pager]
- %PROGRAM_FILES%\Microsoft\MSFuckerBot.exe
- <SYSTEM32>\hurct.exe
- %TEMP%\bs.exe
- %PROGRAM_FILES%\MSFuckerBot1.0.exe
- %PROGRAM_FILES%\Microsoft\Bot.ini
- %TEMP%\bs.exe
- 'www.ex###xss.com':80
- www.ex###xss.com/xiaoka/exprexss.bmp
- www.ex###xss.com/xiaoka/exprexss.jpg
- www.ex###xss.com/xiaoka/exprexss.gif
- DNS ASK www.ha##506.com
- DNS ASK www.ex###xss.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'