Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'msmsgs' = '%ProgramFiles(x86)%\Messenger\msmsgs.exe'
- %WINDIR%\temp\video.flv
- %WINDIR%\temp\d1.exe
- %ProgramFiles(x86)%\messenger\msmsgs.exe
- %ProgramFiles(x86)%\messenger\source.xml
- 'de###wer.com':80
- http://de###wer.com/desk2/submit_ticket.php
- DNS ASK de###wer.com
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'SystemTray_Main' WindowName: ''
- '%WINDIR%\temp\d1.exe'
- '%ProgramFiles(x86)%\messenger\msmsgs.exe'
- '%WINDIR%\syswow64\rundll32.exe' <SYSTEM32>\shell32.dll,OpenAs_RunDLL %WINDIR%\temp\video.flv