Техническая информация
- [<HKCU>\software\microsoft\windows\currentversion\run] 'Server.exe' = '%TEMP%\57yhyh.ExE'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Dropbox' = '%TEMP%\57yhyh.ExE'
- %APPDATA%\microsoft\windows\start menu\programs\startup\dropbox.exe
- '%TEMP%\57yhyh.exe'
- %TEMP%\57yhyh.exe
- 'bl#####imane.ddns.net':110
- DNS ASK bl#####imane.ddns.net
- ClassName: 'Shell_traywnd' WindowName: ''