Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'travel' = '%APPDATA%\Travel\diagnostics.exe'
- '%APPDATA%\Travel\diagnostics.exe'
- %APPDATA%\Travel\diagnostics.exe
- 'sx##.#erveblog.net':5223
- DNS ASK sx##.#erveblog.net
- ClassName: 'Indicator' WindowName: '(null)'