Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'windows.exe' = '<SYSTEM32>\windows.exe'
- %TEMP%\server.exe
- %TEMP%\saveflash.exe
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\windows.exe
- %TEMP%\nsf4.tmp\LangDLL.dll
- %TEMP%\saveflash.exe
- %TEMP%\server.exe
- 'pr##.no-ip.info':2003
- 'r5###.no-ip.info':2003
- 'x8.##ndns.info':2003
- DNS ASK pr##.no-ip.info
- DNS ASK r5###.no-ip.info
- DNS ASK x8.##ndns.info
- ClassName: 'Shell_TrayWnd' WindowName: ''