Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Update' = '%HOMEPATH%\Desktop\filename.exe'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Update' = '%HOMEPATH%\Desktop\filename.exe'
- filename.exe
- %HOMEPATH%\desktop\filename.exe
- %TEMP%\tmpc245.tmp
- %TEMP%\tmpc3ad.tmp
- %TEMP%\af7b1841c6a70c858e3201422e2d0bea.dat
- 'ch####p.dyndns.org':80
- http://ch####p.dyndns.org/
- DNS ASK ch####p.dyndns.org
- DNS ASK ro####skitsx.info
- DNS ASK in####blesoft.net
- '%HOMEPATH%\desktop\filename.exe'