Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'DF61D2D9' = '%TEMP%\nagiu.exe'
- [<HKLM>\SYSTEM\ControlSet001\services\ealydxbyqc] 'Start' = '00000002'
- '%TEMP%\nagiu.exe' -svc
- %TEMP%\nagiu.exe
- DNS ASK dn#.##ftncsi.com
- DNS ASK pi##.himpi.com
- ClassName: 'Shell_TrayWnd' WindowName: ''