Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'msnmessnger' = ''
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{TQ3322LT-0PWK-O8KJ-R031-E54MX27RV2Q5}] 'StubPath' = '<SYSTEM32>\installers\msnmessenger.exe Restart'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'msnmessnger' = ''
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'msnmessnger' = ''
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'msnmessnger' = ''
- Компонент восстановления системы (SR)
- '%TEMP%\0'
- '<SYSTEM32>\wscript.exe' "%TEMP%\reg.vbs"
- '<SYSTEM32>\wscript.exe' "%TEMP%\exec.vbs"
- '<SYSTEM32>\services.exe'
- <SYSTEM32>\alg.exe
- %TEMP%\exec.vbs
- %TEMP%\reg.vbs
- %TEMP%\0
- <SYSTEM32>\installers\msnmessenger.exe
- 'sn######789.bounceme.net':82
- DNS ASK sn######789.bounceme.net
- ClassName: 'Indicator' WindowName: ''