Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'MSUPD32' = '%APPDATA%\pefnetm.exe'
- %APPDATA%\pefnetm.exe
- %APPDATA%\pefnetm.exe
- 'do#####t.cleansite.us':443
- 'do#####t.cleansite.us':80
- do#####t.cleansite.us/0000/a244406.asp
- DNS ASK do#####t.cleansite.us
- ClassName: 'Indicator' WindowName: ''