Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows32' = '%WINDIR%\system\wini.exe'
- %WINDIR%\system\wini.exe
- 'wi####rstuart.com':80
- http://wi####rstuart.com/index.php?op#############################################
- DNS ASK wi####rstuart.com
- ClassName: 'NDDEAgnt' WindowName: 'NetDDE Agent'