Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'system' = '<SYSTEM32>\system.exe'
- <Drive name for removable media>:\AutoRun.inf
- %TEMP%\1.tmp
- C:\AutoRun.inf
- 'e1#.#z889.com':8080
- DNS ASK e1#.#z889.com
The page may not load correctly.
Added to the Dr.Web virus database: 2013-08-25
Virus description added: 2013-08-25