Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'notepad.exe' = '%APPDATA%\NNN-LTMDSEXOBM\notepad.exe'
- '%APPDATA%\NNN-LTMDSEXOBM\notepad.exe'
- %APPDATA%\NNN-LTMDSEXOBM\notepad.exe
- %TEMP%\nsq4.tmp\watchman.dll
- %APPDATA%\We Were Here.log
- %TEMP%\nsx2.tmp\watchman.dll
- %APPDATA%\NNN-LTMDSEXOBM\notepad.exe
- %TEMP%\nsq4.tmp\watchman.dll
- %TEMP%\nsx2.tmp\watchman.dll
- 'bi##oint.ws':80
- DNS ASK bi##oint.ws