Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '12452' = '<SYSTEM32>\msoreca.exe'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{6648C272-2F46-56E4-52E1-FB05D5997796}] 'StubPath' = '<SYSTEM32>\msoreca.exe'
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\msoreca.exe
- '67.##5.160.76':80
- 'ta##8.com':443
- DNS ASK www.ya##o.com
- DNS ASK ta##8.com