Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'msnmsger' = 'C:\Extracted\1.exe'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{33526185-B714-5C2E-B63C-6B5FB0E8E130}] 'StubPath' = 'C:\Extracted\1.exe'
- C:\Extracted\SP27213.exe
- C:\Extracted\1.exe
- %TEMP%\wel1.tmp
- %TEMP%\ext4.tmp
- %TEMP%\plf3.tmp
- %TEMP%\ext2.tmp
- %TEMP%\sfx.ini
- C:\Extracted\SP27213.exe
- C:\Extracted\1.exe
- %TEMP%\wel1.tmp
- %TEMP%\ext4.tmp
- %TEMP%\sfx.ini
- %TEMP%\ext2.tmp
- 'mr####dz.no-ip.org':3460
- DNS ASK mr####dz.no-ip.org
- ClassName: 'Shell_TrayWnd' WindowName: ''