Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\The Htool] 'Start' = '00000002'
- '%WINDIR%\Htool.exe'
- '%WINDIR%\Temp\Б¬·ўіМРт.exe'
- '%WINDIR%\Temp\Server_Setup.exe'
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\uninstal.bat
- %WINDIR%\Htool.exe
- %WINDIR%\uninstal.bat
- %WINDIR%\Temp\Server_Setup.exe
- %WINDIR%\Temp\Б¬·ўіМРт.exe
- %WINDIR%\Htool.exe
- %WINDIR%\Temp\Server_Setup.exe
- 'xu######4727.web-183.com':80
- xu######4727.web-183.com/ip.txt
- DNS ASK xu######4727.web-183.com
- ClassName: '#32771' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'AutoHotkey' WindowName: '%WINDIR%\Temp\????????.exe'