Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'taskngr.exe' = '"%WINDIR%\taskngr.exe"'
- '%WINDIR%\taskngr.exe'
- %WINDIR%\taskngr.exe
- 'yz.###uangtou.com':80
- 'gx#.#3322.net':1211
- 'localhost':1037
- http://yz.###uangtou.com/api/xmlapi.asmx/GetInfo
- DNS ASK yz.###uangtou.com
- DNS ASK gx#.#3322.net
- ClassName: 'Progman' WindowName: ''