Техническая информация
- [<HKLM>\software\Wow6432Node\microsoft\windows\currentversion\Policies\Explorer\Run] '18085' = '%ProgramFiles%\locals~1\Temp\msesiu.exe'
- %WINDIR%\syswow64\svchost.exe
- %ProgramFiles%\locals~1\temp\msesiu.exe
- '<DNS_SERVER>':53
- '10#.#34.34.104':80
- '%WINDIR%\syswow64\svchost.exe'