Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'System' = '<SYSTEM32>\Microsoft\System.exe'
- <SYSTEM32>\microsoft\system.exe
- %WINDIR%\1426755587
- 'pu####apo.uuuq.com':21
- DNS ASK st####.#essenger.msn.com
- DNS ASK pu####apo.uuuq.com
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%WINDIR%\explorer.exe' http://st####.#essenger.msn.com/' (со скрытым окном)
- '%WINDIR%\explorer.exe' http://st####.#essenger.msn.com/
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\dw20.exe' -x -s 892