Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Net CLR sanae] 'ImagePath' = '%WINDIR%\atieclk.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Net CLR sanae] 'Start' = '00000002'
- '%WINDIR%\atieclk.exe'
- '<SYSTEM32>\cmd.exe' /c afc9fe2f418b00a0.bat
- <Текущая директория>\afc9fe2f418b00a0.bat
- %WINDIR%\atieclk.exe
- 'www.ai###gji.com':8897
- 'ww#####ng677.vicp.cc':2014
- DNS ASK www.ai###gji.com
- DNS ASK ww#####ng677.vicp.cc
- DNS ASK bu#.##gongji.com