Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Explorer' = '<SYSTEM32>\msrstart.exe'
- [<HKLM>\SOFTWARE\Classes\txtfile\shell\open\command] '' = '"<SYSTEM32>\nxtepad.exe" "%1"'
- '<SYSTEM32>\w.exe'
- <SYSTEM32>\nxtepad.exe
- <SYSTEM32>\sopidkc.exe
- %TEMP%\mtaw35278.dll
- <SYSTEM32>\msrstart.exe
- <SYSTEM32>\umtcdtw.sys
- <SYSTEM32>\tpszxyd.sys
- <SYSTEM32>\afisicx.exe
- <SYSTEM32>\comsa32.sys
- <SYSTEM32>\w.exe
- 'js###ivity.com':8392
- '74.##.37.210':8392
- '17#.#33.126.2':8392
- 'bf##.com':8392
- '74.##.201.210':8392
- '20#.#3.250.162':8392
- DNS ASK js###ivity.com
- DNS ASK bf##.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''