Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'keyis' = '"<Полный путь к файлу>"'
- '<SYSTEM32>\mshta.exe' "<HTML><HEAD><HTA:APPLICATION APPLICATIONNAME='GetParentPID' WINDOWSTATE='minimize' SHOWINTASKBAR='no'</HEAD></HTML>"
- <SYSTEM32>\mshta.exe
- [<HKCU>\Software\Microsoft\Internet Account Manager]
- [<HKCU>\Software\Microsoft\Internet Account Manager\Accounts]
- '94.##0.191.201':25
- 'www.wh###smyip.com':80
- 'localhost':1039
- http://www.wh###smyip.com/automation/n09230945.asp
- DNS ASK sm##.mail.ru
- DNS ASK www.wh###smyip.com