Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'MicrosoftUpdate' = '%TEMP%\4AD5.tmp.exe'
- %TEMP%\4AD5.tmp.exe
- 'dk##zh.org':443
- DNS ASK dn#.##ftncsi.com
- DNS ASK dk##zh.org
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: 'WordPadClass' WindowName: '(null)'