Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'run' = 'c:\B587593msrn587593\MSN.lnk'
- 'c:\B587593msrn587593\ALYao.exe' "c:\B587593msrn587593\Qcccg.dll",InitSkin
- '<SYSTEM32>\PING.EXE' 127.0.0.1 -n 3
- C:\B587593msrn587593\MSN.lnk
- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MSN.lnk
- C:\B587593msrn587593\Qcccg.dll
- C:\B587593msrn587593\ALYao.exe
- '19#.#4.241.106':805
- '14#.#.131.59':8761
- DNS ASK dn#.##ftncsi.com