Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ddown' = '%HOMEPATH%\Start Menu\Programs\down.exe'
- '%HOMEPATH%\Start Menu\Programs\down.exe'
- %HOMEPATH%\Start Menu\Programs\down.exe
- %HOMEPATH%\Start Menu\Programs\down.exe
- 'an####eatsystem.com':80
- an####eatsystem.com/deneme/deneme.txt
- DNS ASK an####eatsystem.com
- ClassName: 'Indicator' WindowName: '(null)'