Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'process' = '%APPDATA%\processx\process.exe'
- %WINDIR%\syswow64\explorer.exe
- %APPDATA%\processx\process.exe
- DNS ASK dr##box.com
- DNS ASK se######template0000.dad
- DNS ASK se######template0000.click
- '%WINDIR%\syswow64\explorer.exe'