Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'run' = '%PROGRAM_FILES%\131078\Ppdh.exe'
- %PROGRAM_FILES%\131078\Ppdh.exe
- <SYSTEM32>\ping.exe 127.0.0.1 -n 3
- %PROGRAM_FILES%\131078\Ppdh.exe
- %PROGRAM_FILES%\131078\common\RCX1.tmp
- %PROGRAM_FILES%\131078\common\Utility.dll
- %PROGRAM_FILES%\131078\common\Utility.dll
- %PROGRAM_FILES%\131078\common\RCX1.tmp в %PROGRAM_FILES%\131078\common\Utility.dll
- '96.##7.139.188':10086