Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'JPWHOY' = '%TEMP%\Skyp\TBWOZY.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\JPWHOY.lnk
- %TEMP%\Skyp\TBWOZY.exe
- 'ki#####e.duckdns.org':1608
- 'ip###ore.com':80
- http://ip###ore.com/checkip/
- DNS ASK ki#####e.duckdns.org
- DNS ASK ip###ore.com