Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'fgtyu' = '%APPDATA%\fgt\tfgh.exe.exe'
- '%APPDATA%\dro.exe'
- dro.exe
- %APPDATA%\dro.exe
- %APPDATA%\fgt\tfgh.exe.exe
- 'ch####eyns-bg.eu':80
- '79.##4.225.74':1973
- DNS ASK ch####eyns-bg.eu
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding