Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Klass' = '%WINDIR%\klassx.exe'
- %WINDIR%\klassx.exe
- %WINDIR%\dir
- %WINDIR%\klassx.exe
- %WINDIR%\name
- %TEMP%\~DF1702.tmp
- 'to#####oject.no-ip.org':6985
- DNS ASK to#####oject.no-ip.org
- ClassName: 'Indicator' WindowName: ''