Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Micro System Software' = '"%PROGRAM_FILES%\MSNLive\msnn.exe"'
- %PROGRAM_FILES%\MSNLive\msnn.exe
- %PROGRAM_FILES%\MSNLive\link.exe
- %PROGRAM_FILES%\MSNLive\wget.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\get[1].php
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- %PROGRAM_FILES%\MSNLive\msnn.exe
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- 'localhost':1038
- 'www.ku###serv.info':80
- www.ku###serv.info/con/get.php?na################################################
- www.ku###serv.info/con/reg.php?ve###################################################
- DNS ASK www.ku###serv2.info
- DNS ASK www.ku###serv.info
- '<IP-адрес в локальной сети>':1037
- ClassName: '' WindowName: 'Kuala Software'
- ClassName: 'Shell_TrayWnd' WindowName: ''