Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'e216c1da2a291c8b595bb7027107296a' = '"%APPDATA%\Server.exe" ..'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'e216c1da2a291c8b595bb7027107296a' = '"%APPDATA%\Server.exe" ..'
- %APPDATA%\microsoft\windows\start menu\programs\startup\e216c1da2a291c8b595bb7027107296a.exe
- %APPDATA%\server.exe
- 'ta###.publicvm.com':5
- DNS ASK ta###.publicvm.com
- '%APPDATA%\server.exe'