Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'heheyst' = '%WINDIR%\system\hehey6.exe'
- <SYSTEM32>\logonui.exe /status /shutdown
- %WINDIR%\system\hehey6.exe
- '93.##8.134.11':25
- DNS ASK sm##.yandex.ru
- '<IP-адрес в локальной сети>':1035
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'StatusWindowClass' WindowName: ''
- ClassName: 'Indicator' WindowName: ''