Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Explorer' = '<SYSTEM32>\msrstart.exe'
- [<HKLM>\SOFTWARE\Classes\txtfile\shell\open\command] '' = '"<SYSTEM32>\nxtepad.exe" "%1"'
- %TEMP%\mtaw97300.dll
- <SYSTEM32>\msrstart.exe
- <SYSTEM32>\nxtepad.exe
- 'js###ivity.com':8392
- '74.##.37.210':8392
- '17#.#33.126.2':8392
- 'bf##.com':8392
- '74.##.201.210':8392
- '20#.#3.250.162':8392
- DNS ASK js###ivity.com
- DNS ASK bf##.com