Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\ddraw] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\ddraw] 'ImagePath' = '"%WINDIR%\SysWOW64\atl100\ddraw.exe"'
- 'ddraw' "%WINDIR%\SysWOW64\atl100\ddraw.exe"
- 'ddraw' %WINDIR%\SysWOW64\atl100\ddraw.exe
- из <Полный путь к файлу> в %WINDIR%\syswow64\atl100\ddraw.exe
- '24.##.32.186':80
- http://24.##.32.186/XG35QGqtM0YIuoF/gtVqyveS/ofdo0xw6HSIwlINWu81/bDzMLViwLyO4VidwoX/5XhFuYDH7rEZmRen/cLxxxW1CVicsoGL/