Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\chmod.eu.url
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\.Identifier
- %ALLUSERSPROFILE%\Application Data\Frames\chmod.exe
- <SYSTEM32>\.Identifier
- 'wi###########der-process.myactivedirectory.com':35360
- DNS ASK wi###########der-process.myactivedirectory.com
- '%ALLUSERSPROFILE%\Application Data\Frames\chmod.exe'
- '<SYSTEM32>\svchost.exe'