Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'МЪС¶QQ' = 'C:\1.exe'
- 'C:\1.exe'
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\shell32.dll,OpenAs_RunDLL C:\1.mp4
- C:\falcon.dll
- C:\qybrowser_log.txt
- C:\1.mp4
- C:\1.exe
- '66##.eatuo.com':1688
- DNS ASK 66##.eatuo.com
- ClassName: 'EDIT' WindowName: ''