Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\UpdateService] 'Start' = '00000002'
- '<SYSTEM32>\UpdateService.exe' -install
- '%TEMP%\CSS_<Имя вируса>.exe'
- '%TEMP%\1050.exe'
- '<SYSTEM32>\ipconfig.exe' /all
- '<SYSTEM32>\rundll32.exe' %TEMP%\spoolsv.cpl,gmmain %WINDIR%\csapix.dll
- <SYSTEM32>\services.exe
- <SYSTEM32>\UpdateModule.dll
- <SYSTEM32>\UpdateService.exe
- <SYSTEM32>\Install.xml
- %PROGRAM_FILES%\Update\Files.xml
- %TEMP%\spoolsv.cpl
- %TEMP%\1050.tmp
- %TEMP%\CSS_<Имя вируса>.exe
- %TEMP%\1050.exe
- %WINDIR%\csapix.dll
- %TEMP%\csapix.tmp
- <SYSTEM32>\Install.xml
- %TEMP%\csapix.tmp
- 'ww##.#m-server.com':80
- 'www.dz##.com':80
- www.dz##.com/060629/Update.xml
- ww##.#m-server.com/gm/LiveUpdate.do?&u######################################
- www.dz##.com/SGD/post.aspx
- DNS ASK ww##.#m-server.com
- DNS ASK www.dz##.com
- DNS ASK www.ba##u.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''