Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '0AE45177' = '%APPDATA%\Roaming\0AE45177\bin.exe'
- '<SYSTEM32>\winver.exe'
- <SYSTEM32>\taskhost.exe
- %APPDATA%\Roaming\0AE45177\bin.exe
- DNS ASK jy####howqqf.com
- DNS ASK ru####xgpyhg.com
- DNS ASK ue####txttxw.com
- DNS ASK hk####jguudc.com
- DNS ASK ri####wfcpqq.com
- DNS ASK sw####kebree.com
- DNS ASK dn#.##ftncsi.com
- DNS ASK fa###oock.ru
- DNS ASK qn####cphhpo.com
- DNS ASK wj####tddwwo.com
- DNS ASK ql####djdtpl.com
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''