Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{EA4C11A4-81BC-6650-07B0-5B4E2AE3B8F6}] 'StubPath' = '<SYSTEM32>:winupdate.exe'
- <SYSTEM32>\server.exe
- <SYSTEM32>\Sythe Autofighter 1.0.exe
- %WINDIR%\Explorer.EXE
- <SYSTEM32>:winupdate.exe
- <SYSTEM32>\Sythe Autofighter 1.0.exe
- <SYSTEM32>\server.exe
- 'ka#.#yftp.biz':4400
- 'ka#.##unceme.net':4400
- 'ka#.myvnc':4400
- 'ka####.no-ip.biz':4400
- DNS ASK ka#.#yftp.biz
- DNS ASK ka#.##unceme.net
- DNS ASK ka#.myvnc
- DNS ASK ka####.no-ip.biz
- ClassName: 'Shell_TrayWnd' WindowName: ''