Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'dfg' = '%TEMP%\KinG.exe'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{A44343E7-4393-7FBD-4876-FA67FDDD2CD8}] 'StubPath' = '%TEMP%\KinG.exe'
- %TEMP%\KinG.exe
- <SYSTEM32>\rundll32.exe <SYSTEM32>\shimgvw.dll,ImageView_Fullscreen %TEMP%\______3.jpg
- %TEMP%\KinG.exe
- %TEMP%\______3.jpg
- '7o###.no-ip.biz':3460
- DNS ASK 7o###.no-ip.biz
- '<IP-адрес в локальной сети>':1035
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'ShImgVw:CPreviewWnd' WindowName: ''