Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'NexusAV' = '%APPDATA%\AntiVirus\AVScanner.scr'
- '%APPDATA%\AntiVirus\AVScanner.scr' /S
- %APPDATA%\AntiVirus\AVScanner.scr
- 'bt#####e.bounceme.net':3362
- DNS ASK bt#####e.bounceme.net
- ClassName: 'Indicator' WindowName: '(null)'