Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'enuriupdate' = ''
- <SYSTEM32>\msvbvm60.dll
- <SYSTEM32>\enuriupdate.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\run[1].php
- %TEMP%\rad61889.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\enuriupdate[1].htm
- <SYSTEM32>\enuriupdate.exe
- <SYSTEM32>\MSINET.OCX
- <SYSTEM32>\VB6KO.DLL
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\run[1].php
- 'up#.##sualwork.kr':80
- 'pr#.##mworld.com':80
- 'localhost':1037
- pr#.##mworld.com/run.php
- up#.##sualwork.kr/enuriupdate.php
- DNS ASK up#.##sualwork.kr
- DNS ASK pr#.##mworld.com