Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'twr' = '"%TEMP%\twr14.exe"'
- %TEMP%\twr14.exe
- 'www.ir##hpub.fo':80
- 'bo###pro.com':80
- 'ga###sports.net':80
- 'se#####onmusic.co.za':80
- www.ir##hpub.fo/.sys.php?ac###############
- bo###pro.com/.sys.php?ac###############
- ga###sports.net/.sys.php?ac###############
- se#####onmusic.co.za/.sys.php?ac###############
- DNS ASK www.ir##hpub.fo
- DNS ASK bo###pro.com
- DNS ASK ga###sports.net
- DNS ASK se#####onmusic.co.za
- ClassName: 'Shell_TrayWnd' WindowName: ''