Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe] 'Debugger' = '%PROGRAM_FILES%\expdebug.exe'
- <SYSTEM32>\svchost.exe
- %PROGRAM_FILES%\expdebug.exe
- %PROGRAM_FILES%\expdebug.exe
- 'bo###a888.cn':80
- bo###a888.cn/web/s.php?
- DNS ASK bo###a888.cn
- ClassName: 'SunAwtFrame' WindowName: ''