Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'sxrmW' = '%LOCALAPPDATA%\sxrmW.url'
- C:\users\public\temp
- %LOCALAPPDATA%\binance-updater\wmrxsrew.exe
- %LOCALAPPDATA%\binance-updater\wmrxs
- %LOCALAPPDATA%\sxrmw.url
- C:\users\public\temp
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- DNS ASK 1d#v.ws
- DNS ASK microsoft.com
- DNS ASK sg####.#l.files.1drv.com