Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'windows' = '"%ProgramFiles(x86)%\windows\windows.exe" -a /a'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'windows' = '"%ProgramFiles(x86)%\windows\windows.exe" -a /a'
- %TEMP%\svhost.exe
- %ProgramFiles(x86)%\windows\windows.exe
- DNS ASK dn#.####neshopserver.online
- DNS ASK ne####verr.ddns.net