Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\PgJTacYOKPUM.lnk
- '<SYSTEM32>\wscript.exe'
- '%APPDATA%\fFOS.exe' "%APPDATA%\IdVha.au3"
- <SYSTEM32>\wscript.exe
- <SYSTEM32>\.Identifier
- %APPDATA%\IdVha.au3
- %APPDATA%\fFOS.exe
- <SYSTEM32>\.Identifier
- %HOMEPATH%\ULxOC1zXgfPqjyx4\IdVha.au3
- %HOMEPATH%\ULxOC1zXgfPqjyx4\fFOS.exe
- %APPDATA%\fFOS.exe в %HOMEPATH%\ULxOC1zXgfPqjyx4\fFOS.exe
- %APPDATA%\IdVha.au3 в %HOMEPATH%\ULxOC1zXgfPqjyx4\IdVha.au3
- 'd0####5.duckdns.org':10044
- 'su#####win.dyndns.pro':10044
- 'mi######t01.system-ns.net':10044
- DNS ASK d0####5.duckdns.org
- DNS ASK su#####win.dyndns.pro
- DNS ASK mi######t01.system-ns.net
- ClassName: 'Shell_TrayWnd' WindowName: ''