Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'Load' = '%LOCALAPPDATA%\Broker Agent\Broker Agent.exe�'
- '%TEMP%\loader.exe'
- %TEMP%\loader.exe
- %LOCALAPPDATA%\broker agent\broker agent.exe
- %TEMP%\loader.exe в %LOCALAPPDATA%\broker agent\broker agent.exe
- %LOCALAPPDATA%\broker agent\broker agent.exe
- http://my######udes.serveblog.net/bat/serverstatus.exe
- DNS ASK my######udes.serveblog.net