Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'AppRt4b08' = '%LOCALAPPDATA%\AppRt4b08\apprt4b08.exe'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'AppSvc4b08' = '%LOCALAPPDATA%\Programs\4b08\svc4b08.exe'
- nul
- %LOCALAPPDATA%\apprt4b08\apprt4b08.exe
- %LOCALAPPDATA%\programs\4b08\svc4b08.exe
- '20#.#94.54.131':6543
- '%LOCALAPPDATA%\apprt4b08\apprt4b08.exe'
- '%LOCALAPPDATA%\programs\4b08\svc4b08.exe'
- '%LOCALAPPDATA%\apprt4b08\apprt4b08.exe' (со скрытым окном)
- '%LOCALAPPDATA%\programs\4b08\svc4b08.exe' (со скрытым окном)