Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'run' = 'C:\Byjir\Spvr.exe'
- C:\Byjir\Spvr.exe
- <SYSTEM32>\ping.exe 127.0.0.1 -n 3
- C:\Byjir\RCX1.tmp
- C:\Byjir\Spvr.exe
- <SYSTEM32>\ms060102.log
- C:\Byjir\PotPlayer.dll
- C:\Byjir\PotPlayer.dll
- C:\Byjir\RCX1.tmp в C:\Byjir\PotPlayer.dll
- '1.###an1004.com':5853
- DNS ASK 1.###an1004.com
- ClassName: 'Indicator' WindowName: ''