Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '1' = '%WINDIR%\Temp\88E6680F.exe'
- %WINDIR%\Temp\88E6680F.exe
- 'my#p.ru':80
- 'kn#####33.site40.net':80
- 'sp##pay.ru':80
- '2i#.ru':80
- my#p.ru/
- 2i#.ru/
- kn#####33.site40.net/knock.php
- sp##pay.ru/sppi/index.php
- sp##pay.ru/sppi/
- DNS ASK my#p.ru
- DNS ASK kn#####33.site40.net
- DNS ASK sp##pay.ru
- DNS ASK 2i#.ru
- ClassName: '' WindowName: '?????? ?????????'
- ClassName: '' WindowName: '??? ?????????'
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: '????????? ????? Windows'