Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{B969325F-CD97-4b93-B752-4E7958062452}] 'stubpath' = '<SYSTEM32>\regsvr32.exe /s <SYSTEM32>\msrctf60.dll'
- [<HKLM>\SYSTEM\ControlSet001\Services\wuauserv\Parameters] 'ServiceDll' = '<SYSTEM32>\msrctf60.dll'
- [<HKLM>\SYSTEM\ControlSet001\Services\wuauserv] 'Start' = '00000002'
- '<SYSTEM32>\rundll32.exe' "<SYSTEM32>\msrctf60.dll",NlaNotEqual
- '<SYSTEM32>\cmd.exe' /c del <Полный путь к вирусу> >> NUL
- '<SYSTEM32>\regsvr32.exe' /s "<SYSTEM32>\msrctf60.dll"
- <SYSTEM32>\msrctf60.tmp
- <SYSTEM32>\msrctf60.tmp в <SYSTEM32>\msrctf60.dll
- 'localhost':1040
- DNS ASK im#.##ssnews.com
- ClassName: 'Shell_TrayWnd' WindowName: ''