Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe rundll32.exe nynw.wmo mynleeq'
- %WINDIR%\syswow64\svchost.exe
- %TEMP%\5772.tmp
- %WINDIR%\syswow64\nynw.wmo
- DNS ASK ba####ania2010.ru
- '%ProgramFiles%\microsoft office\office14\winword.exe' /Automation -Embedding
- '%WINDIR%\syswow64\svchost.exe'