Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ofice.exe' = '<SYSTEM32>:ofice.exe'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{1699E201-E999-1B29-146E-3A6602E0FC8E}] 'StubPath' = '<SYSTEM32>:ofice.exe'
- %WINDIR%\Explorer.EXE
- <SYSTEM32>:ofice.exe
- 'ki####10.no-ip.org':3460
- DNS ASK ki####10.no-ip.org