Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'MSI30-RC1' = '%APPDATA%\MSI30-RC1\MSI30-RC1.com'
- %APPDATA%\MSI30-RC1\MSI30-RC1.com
- <SYSTEM32>\svchost.exe
- %WINDIR%\explorer.exe
- %APPDATA%\MSI30-RC1\MSI30-RC1.com
- %APPDATA%\MSI30-RC1\MSI30-RC1.com
- 'za##3944.in':80
- '11#.#11.111.7':80
- '11#.#11.111.8':80
- '11#.#11.111.3':80
- za##3944.in/index.php?r=#####
- 11#.#11.111.8/index.php?r=###
- 11#.#11.111.7/index.php?r=###
- DNS ASK za##3944.in
- '<IP-адрес в локальной сети>':1036
- ClassName: 'Indicator' WindowName: ''