Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsMediaPlayerE' = '%APPDATA%\WindowsMediaPlayerE\WindowsMediaPlayerE.com'
- <SYSTEM32>\msiexec.exe
- %TEMP%\1.tmp
- %TEMP%\2.tmp
- %APPDATA%\WindowsMediaPlayerE\WindowsMediaPlayerE.com
- <Полный путь к файлу>
- '13#.#55.73.90':53
- '5.###.183.146':53
- '19#.#83.98.154':53
- '54.##6.38.98':53
- '16#.#3.248.170':53
- '19#.#54.226.249':53
- '34.##0.147.125':53
- '82.#96.9.45':53
- '17#.#04.136.243':53
- '18#.#33.72.100':53
- '31.#.135.232':53
- '89.##.27.167':53
- '18#.#21.170.176':53
- '19#.#83.98.66':53
- '13#.#9.23.241':53
- '23.##.60.240':53
- '20#.#8.192.10':53
- '20#.#6.32.19':53
- '18#.#65.200.156':53
- '51.##4.25.115':53
- '10#.#38.186.189':53
- ClassName: '' WindowName: ''
- '<SYSTEM32>\msiexec.exe'