Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Jklmno Qrstuvwx Abc] 'ImagePath' = 'C:\windasdalogon.exe -k ggipmg'
- [<HKLM>\SYSTEM\ControlSet001\Services\Jklmno Qrstuvwx Abc] 'Start' = '00000002'
- 'C:\windasdalogon.exe' -k ggipmg
- C:\windasdalogon.exe
- '49.#.143.18':8080