Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\NationalVM.] 'Start' = '00000002'
- <SYSTEM32>\boblou.exe
- <SYSTEM32>\taskkill.exe /f /t /im KSafeTray.exe
- <SYSTEM32>\boblou.exe
- 'zw####88.gicp.net':4851
- DNS ASK zw####88.gicp.net
- ClassName: '' WindowName: ''