Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'comime' = '<SYSTEM32>:PHIME2010.EXE'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{0CA00184-F40F-015E-6162-FDEFA03EC245}] 'StubPath' = '<SYSTEM32>:PHIME2010.EXE'
- %WINDIR%\Explorer.EXE
- <SYSTEM32>:PHIME2010.EXE
- '21#.#2.125.98':53
- 'ms######.sellclassics.com':53
- DNS ASK ms######.sellClassics.com