Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'HNUTPOXRnwPQ' = '%TEMP%\ennpte59i5.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'HNUTPOXRnwPQ' = '%TEMP%\ennpte59i5.exe'
- '%TEMP%\ennpte59i5.exe'
- %TEMP%\hfe978whjeuihdsufh.tmp
- %TEMP%\ennpte59i5.exe
- %TEMP%\ennpte59i5.exe
- 'ac##md.com':80
- DNS ASK ac##md.com
- ClassName: 'Indicator' WindowName: '(null)'