Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'aDx87N' = '%HOMEPATH%\dNt78B\cbsSu.exe'
- '<SYSTEM32>\svchost.exe'
- <SYSTEM32>\svchost.exe
- %TEMP%\~a21524.log
- %TEMP%\vUh31L.BE4
- %TEMP%\aut1.tmp
- %TEMP%\vUh31L.BE4
- %TEMP%\vUh31L.BE4
- %TEMP%\aut1.tmp
- 'mu#####treme.no-ip.org':3152
- DNS ASK mu#####treme.no-ip.org
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'