Техническая информация
- %TEMP%\1849.exe
- 'wi####iaplayer.com':80
- http://www.wi####iaplayer.com/direct-download.html?ve#####################################################
- DNS ASK wi####iaplayer.com
- ClassName: '' WindowName: 'CoolMediaPlayer'
- ClassName: '' WindowName: 'MediaPlayer'
- '%WINDIR%\syswow64\reg.exe' ADD HKCU\Software\TR12 /v uni /t REG_SZ /d 1' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD HKCU\Software\TR12 /v uni /t REG_SZ /d 1