Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'XXXXXXF05EB60D' = '%WINDIR%\XXXXXXF05EB60D.exe'
- %WINDIR%\XXXXXXF05EB60D.exe
- 'ws##z.oa.to':8080
- DNS ASK ws##z.oa.to
- ClassName: '' WindowName: 'ИрРЗіМРтЙэј¶ЦР'
- ClassName: '' WindowName: '??????????????'