Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'BD' = '"%TEMP%\dc.exe"'
- %TEMP%\dc.exe
- %PROGRAM_FILES%\Outlook Express\win02s.exe
- %TEMP%\dc.exe
- %TEMP%\backdoor.log
- %PROGRAM_FILES%\Outlook Express\win02s.exe
- 'ko#####2.evangelion.nu':9123
- DNS ASK ko#####2.evangelion.nu
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''