Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] ' tkwin32 ' = '<SYSTEM32>\mbf8507.exe'
- Диспетчера задач (Taskmgr)
- <SYSTEM32>\mbf8507.exe
- <SYSTEM32>\xat32dy.dll
- 'localhost':1037
- 'ke#####001.fileave.com':80
- http://ke#####001.fileave.com/
- DNS ASK ke#####001.fileave.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''