Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Adobe After UPD' = '%WINDIR%\winlagon.exe'
- '%WINDIR%\winlagon.exe'
- <SYSTEM32>\MSWINSCK.OCX
- %WINDIR%\winlagon.exe
- %WINDIR%\MSWINSCK.OCX
- 'du#.#o-ip.info':4444
- DNS ASK du#.#o-ip.info
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'