Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'twr' = '"%TEMP%\twr15.exe"'
- %TEMP%\twr15.exe
- 'cu####oductions.com':80
- 'www.ec###raum.ch':80
- 'bo###pro.com':80
- 'www.dr####ythames.com':80
- cu####oductions.com/.sys.php?ac###############
- www.ec###raum.ch/.sys.php?ac###############
- bo###pro.com/.sys.php?ac###############
- www.dr####ythames.com/.sys.php?ac###############
- DNS ASK cu####oductions.com
- DNS ASK www.ec###raum.ch
- DNS ASK www.dr####ythames.com
- DNS ASK bo###pro.com
- '<IP-адрес в локальной сети>':1033
- ClassName: 'Shell_TrayWnd' WindowName: ''