Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Login Component' = '%APPDATA%\Microsoft Login System\winlogon.exe'
- %APPDATA%\Microsoft Login System\winlogon.exe
- '92.##1.164.189':80
- 'wp#d':80
- wp#d/wpad.dat
- 92.##1.164.189/bot/connect.php
- DNS ASK wp#d
- '23#.#55.255.250':1900
- 'localhost':1039
- 'localhost':1038