Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\Wsqqwk wwqcqsem] 'Start' = '00000002'
- '%PROGRAM_FILES%\Windows NT\Iyyesms.exe'
- '<SYSTEM32>\WScript.exe' "C:\1304.vbs"
- C:\1304.vbs
- %PROGRAM_FILES%\Windows NT\Iyyesms.exe
- C:\1304.vbs
- DNS ASK dn#.##ftncsi.com
- DNS ASK co######672847.kmras.com
- ClassName: 'Shell_TrayWnd' WindowName: ''