Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS\CURRENTVERSION\RUN] 'ctmon' = 'C:\Arquivos de programas\Sidebar\new.exe'
- [<HKCU>\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN] 'msnmsr' = 'C:\Arquivos de programas\Sidebar\new.exe'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- 'ne###life.com':80
- http://ne###life.com/order/env.php
- DNS ASK ne###life.com