Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'fe' = '%APPDATA%\yf\dg.exe'
- '%APPDATA%\fghro.exe'
- fghro.exe
- %APPDATA%\fghro.exe
- %APPDATA%\yf\dg.exe
- '18#.#57.160.147':4444
- '18#.#57.160.147':1975
- http://18#.###.160.147:4444/as.exe via 18#.#57.160.147
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding