Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'securityscan' = '%WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe'
- '%WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe'
- '%APPDATA%\HWRe.exe' NIAXT
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\.Identifier
- %APPDATA%\NIAXT
- %APPDATA%\HWRe.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\.Identifier
- 'mo####eal.ddns.net':1975
- DNS ASK mo####eal.ddns.net
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''