Техническая информация
- %ALLUSERSPROFILE%\0
- %ALLUSERSPROFILE%\5a8720e866\hkmoov.exe
- '255.255.255.255':80
- DNS ASK ha##ous.net
- '%ALLUSERSPROFILE%\5a8720e866\hkmoov.exe'
- '%WINDIR%\syswow64\reg.exe' ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" /f /v Startup /t REG_SZ /d %ALLUSERSPROFILE%\5a8720e866