Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%WINDIR%\RedLeb3.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '<SYSTEM32>\redname3.exe'
- %WINDIR%\RedLeb3.exe
- <SYSTEM32>\redname3.exe
- 'ch###ta.info':80
- ch###ta.info/importes/server.php
- DNS ASK ch###ta.info