Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Taskhost' = '%APPDATA%\taskhost.exe'
- taskhost.exe
- %APPDATA%\taskhost.exe
- %APPDATA%\system.log
- 'mo###ueus.com':80
- DNS ASK ek##ert.net
- DNS ASK mo###ueus.com
- '%APPDATA%\taskhost.exe'