Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SQ Platform' = '%APPDATA%\???¶??????.exe ?(?3?)? ?,??????'
- '%TEMP%\УВКїДЪЗ¶.exe'
- '%APPDATA%\МЪС¶НшРВОЕ.exe'
- %HOMEPATH%\Desktop\SQ ФЖРВОЕ.lnk
- %TEMP%\УВКїДЪЗ¶.exe
- %APPDATA%\МЪС¶НшРВОЕ.exe
- 'k.###udown.com':5555
- 'iw######ygoodbye.lofter.com':80
- iw######ygoodbye.lofter.com/post/3db791_1540641
- DNS ASK k.###udown.com
- DNS ASK iw######ygoodbye.lofter.com
- ClassName: 'Shell_TrayWnd' WindowName: ''