Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'belal2' = '<SYSTEM32>\msn.exe'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{5D5D7875-789F-FF88-1CDA-9B8739FB98C7}] 'StubPath' = '<SYSTEM32>\msn.exe'
- %TEMP%\music.exe
- %WINDIR%\Explorer.EXE
- msnmsgr.exe
- <SYSTEM32>\msn.exe
- %TEMP%\music.exe
- %TEMP%\music.exe.nb5.tmp
- %TEMP%\music.exe.nb5.tmp
- 'cj#.#o-ip.biz':3460
- DNS ASK cj#.#o-ip.biz