Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'run' = 'c:\L110171bvrf110171\MSN.lnk'
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\MSN.lnk
- 'C:\L110171bvrf110171\ALYao.exe' "c:\L110171bvrf110171\Emime.dll",InitSkin
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 3
- C:\L110171bvrf110171\MSN.lnk
- C:\L110171bvrf110171\ALYao.exe
- C:\L110171bvrf110171\Emime.dll
- '11#.#3.223.81':805
- '11#.#3.223.82':8761