Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Run' = ''
- <LS_APPDATA>\%USERNAME%.exe
- 'or#####apontevedra.es':80
- 'gr####asamas.com':80
- '20#.#8.201.22':82
- or#####apontevedra.es/cont/lachita.php
- gr####asamas.com/media/images/AVISO.php
- DNS ASK or#####apontevedra.es
- DNS ASK gr####asamas.com
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'