Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'runSoundAPI' = '%WINDIR%\spoolsv.exe'
- %WINDIR%\spoolsv.exe
- %WINDIR%\system\KB140890.log
- %WINDIR%\system\KB140890.log
- '20#.#3.12.240':80
- http://www.gr####inapse.com.br/sinapsekeylogger/postlog.php via 20#.#3.12.240
- '%WINDIR%\spoolsv.exe'