Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '"%APPDATA%\Security\NRPJsU2R3wA4.exe",explorer.exe'
- %APPDATA%\Imminent\Logs\22-12-2014
- %APPDATA%\Security\NRPJsU2R3wA4.exe
- %APPDATA%\Security\NRPJsU2R3wA4.exe
- 'ra####r2.no-ip.org':5050
- DNS ASK ra####r2.no-ip.org