Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Games Zone Msn' = '"<SYSTEM32>\msn.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Runtime' = '"%APPDATA%\explorers.exe"'
- скрытых файлов
- '<SYSTEM32>\msn.exe'
- '%APPDATA%\explorers.exe'
- <SYSTEM32>\msn.exe
- %APPDATA%\explorers.exe
- <SYSTEM32>\msn.exe
- %APPDATA%\explorers.exe
- 'sa##.com.hk':80
- 'wp#d':80
- wp#d/wpad.dat
- sa##.com.hk/beef/but/gate.php
- DNS ASK sa##.com.hk
- DNS ASK wp#d
- ClassName: 'Indicator' WindowName: '(null)'