Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = 'userinit.exe,jmsdbrcfg.exe,%PROGRAM_FILES%\IEXPL0RER.EXE'
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\jmsdbrcfg.exe
- [<HKCU>\Software\Microsoft\MessengerService]
- %PROGRAM_FILES%\IEXPL0RER.EXE
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\configmsn[1].txt
- <SYSTEM32>\tmsnmon.dll
- <SYSTEM32>\jmsdbrcfg.exe
- <SYSTEM32>\tcpipmsn.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\configmsn[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\configmsn[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\configmsn[1].txt
- 'h1.##pway.com':80
- '74.##5.232.51':25
- 'sm##.gmail.com':465
- 'co####le.no-ip.org':80
- 'localhost':1035
- 'www.al####brasil.com.br':80
- 'di####nho.no-ip.org':80
- co####le.no-ip.org/configmsn.txt
- h1.##pway.com/dianzinho/configmsn.txt
- www.al####brasil.com.br/configmsn.txt
- di####nho.no-ip.org/configmsn.txt
- DNS ASK gm######tp-in.l.google.com
- DNS ASK sm##.gmail.com
- DNS ASK gs####85.google.com
- DNS ASK h1.##pway.com
- DNS ASK www.al####brasil.com.br
- DNS ASK di####nho.no-ip.org
- DNS ASK co####le.no-ip.org
- ClassName: 'YSearchMenuWndClass' WindowName: ''
- ClassName: 'IMWindowClass' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'TskMultiChatForm.UnicodeClass' WindowName: ''