Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'jHHCSpKiYF' = '%APPDATA%\DoFPSqNiCH\cKKPfXkWSY.exe'
- %APPDATA%\dofpsqnich\ckkpfxkwsy.exe
- %TEMP%\rjlxwzjhsxz.bat
- %TEMP%\olzunqp.exe
- 'pr####tedo.ddns.net':667
- DNS ASK pr####tedo.ddns.net
- '%TEMP%\olzunqp.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\Rjlxwzjhsxz.bat" "