Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'VirtualBox Process' = '%WINDIR%\AYHost.exe'
- '<SYSTEM32>\taskkill.exe' /f /t /im RSTray.exe
- %WINDIR%\Explorer.EXE
- %TEMP%\NewAddr.txt
- %WINDIR%\AYHost.exe
- %WINDIR%\AYHost.exe
- %TEMP%\NewAddr.txt
- '10#.#7.108.72':80
- 'localhost':1036
- http://10#.#7.108.72/123.txt
- ClassName: '' WindowName: ''