Техническая информация
- <SYSTEM32>\server.exe
- <SYSTEM32>\server.exe
- %TEMP%\aut2.tmp
- %TEMP%\aut1.tmp
- %TEMP%\__PE-SCRYPTED.BIN
- %TEMP%\aut2.tmp
- %TEMP%\__PE-SCRYPTED.BIN
- %TEMP%\aut1.tmp
- 'sa###.no-ip.info':53320
- DNS ASK sa###.no-ip.info
- ClassName: 'Shell_TrayWnd' WindowName: ''