Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'XXXXXX5BA5D69B' = '%WINDIR%\XXXXXX5BA5D69B.exe'
- %WINDIR%\XXXXXX5BA5D69B.exe
- 'ck####6629.0pe.kr':5555
- DNS ASK ck####6629.0pe.kr
- ClassName: '' WindowName: 'ИрРЗіМРтЙэј¶ЦР'
- ClassName: '' WindowName: '??????????????'