Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Rmaer] 'Start' = '00000002'
- '%WINDIR%\Rmaer.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\BVTLDK.bat
- %TEMP%\BVTLDK.bat
- %WINDIR%\Rmaer.exe
- %WINDIR%\Rmaer.exe
- '11###.rhelper.com':1600
- DNS ASK 11###.rhelper.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'