Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'windows explorer' = '%TEMP%\explorer.exe'
- %TEMP%\install_peurifbc9ukjk.tmp
- %TEMP%\explorer.exe
- %TEMP%\explorer.exe
- %TEMP%\install_peurifbc9ukjk.tmp
- 'ma##.##alanguvenlik.com':587
- DNS ASK ma##.##alanguvenlik.com
- '%TEMP%\explorer.exe'