Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'CTFM0N' = 'c:\B191593dsrk191593\MUpdate.exe c:\B191593dsrk191593\Ejqog.dll,ALSTS_ExecuteAction'
- 'C:\B191593dsrk191593\MUpdate.exe' "c:\B191593dsrk191593\Ejqog.dll",ALSTS_ExecuteAction
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 3
- C:\B191593dsrk191593\MUpdate.exe
- C:\B191593dsrk191593\Ejqog.dll
- '17#.#39.100.228':806
- '17#.#39.100.226':3201
- ClassName: 'Indicator' WindowName: '(null)'