Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'sqlncli' = '%LOCALAPPDATA%\Microsoft\Windows\2575\sqlncli.exe'
- %WINDIR%\syswow64\netsh.exe
- %LOCALAPPDATA%\microsoft\windows\2575\1dd523b7
- %APPDATA%\500507575
- %LOCALAPPDATA%\microsoft\windows\2575\sqlncli.exe
- %APPDATA%\500507575
- 'le####kybest40.in':80
- http://le####kybest40.in/image/adamin/price.php
- DNS ASK le####kybest40.in
- '%WINDIR%\syswow64\netsh.exe'