Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\msupdate] 'Start' = '00000002'
- <SYSTEM32>\msupdate.exe /service
- <SYSTEM32>\RCX1.tmp
- <SYSTEM32>\msupdate.exe
- <SYSTEM32>\msupdate.exe
- 'ms###ate1.net':80
- 'ms###ate1.com':80
- ms###ate1.net/comm.php?us####################
- ms###ate1.com/comm.php?us####################
- ms###ate1.net/newuser.php
- ms###ate1.com/newuser.php
- DNS ASK ms###ate1.net
- DNS ASK ms###ate1.com