Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '' = '<SYSTEM32>\Msnnmsg.exe'
- <SYSTEM32>\Msnnmsg.exe
- <DRIVERS>\etc\sistem.bak
- 've####e.no-ip.org':80
- 've####e.rbcmail.ru':80
- 'localhost':1036
- http://ve####e.rbcmail.ru/hosts.txt
- http://ve####e.no-ip.org/get.aspx?
- DNS ASK ve####e.no-ip.org
- DNS ASK ve####e.rbcmail.ru