Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '3766rq39do' = '%APPDATA%\21eu5wdr02\qfi83syw143wwpo21.exe autorun'
- '%APPDATA%\21eu5wdr02\qfi83syw143wwpo21.exe' start
- %APPDATA%\21eu5wdr02\03g5ywtr32i3a41.txt
- %APPDATA%\21eu5wdr02\qfi83syw143wwpo21.exe
- 're##y.email':80
- re##y.email/gate.php?a=#################
- DNS ASK re##y.email
- ClassName: 'Indicator' WindowName: ''