Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] 'Btmchk' = '{481E867E-AF09-4091-9C98-2C2EC74A3BB8}'
- %WINDIR%\Explorer.EXE
- %CommonProgramFiles%\winafx.log
- 'my###ads.com':80
- my###ads.com/gold/xgate.php
- DNS ASK my###ads.com