Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'AthBtTray' = '%ALLUSERSPROFILE%\\AthBtTray.cpl'
- %APPDATA%\AthBtTray.cpl
- %APPDATA%\svchort.drv
- 'dl.#####oxusercontent.com':80
- dl.#####oxusercontent.com/s/bjpt9lzip4jgku2/ter.otev
- dl.#####oxusercontent.com/s/e0owbuppz2i620x/pre.otev
- DNS ASK dl.#####oxusercontent.com