Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Server' = '%WINDIR%\server.exe'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{3234648B-F9E6-4CA6-B46C-2D750417137D}] 'StubPath' = '%WINDIR%\server.exe'
- %WINDIR%\server.exe
- <SYSTEM32>\cmd.exe /c ""%WINDIR%\melt.bat" "
- %WINDIR%\melt.bat
- %WINDIR%\server.exe
- 'localhost':1005
- ClassName: 'Indicator' WindowName: ''