Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] 'Microsoft Service' = 'c:\hidden\leetbot.exe'
- %WINDIR%\regedit.exe /S c:\hidden\autostart.reg
- <SYSTEM32>\attrib.exe +S +H c:\hidden\leetbot.exe
- <SYSTEM32>\attrib.exe +S +H c:\hidden
- C:\hidden\autostart.reg
- C:\hidden\autostart.reg
- 'we##.tehh4x.com':6667
- DNS ASK we##.tehh4x.com
- ClassName: 'RegEdit_RegEdit' WindowName: ''