Техническая информация
- [HKLM\software\Wow6432Node\microsoft\windows\CurrentVersion\Run] 'Î񵀮ô¶¯Ïî' = '%WINDIR%\shouqan.exe'
- %WINDIR%\shouqan.exe
- %WINDIR%\shouqan.exe
- '11#.#5.134.61':85
- 'ba##u.com':80
- 'ba##u.com':443
- http://www.ba##u.com/
- 'ba##u.com':443
- DNS ASK ba##u.com