Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'hackspa' = '%WINDIR%\server.exe'
- %WINDIR%\AuthShell.dll
- %WINDIR%\server.exe
- %WINDIR%\HFEncrypt.dll
- %WINDIR%\ksomt.doc
- %WINDIR%\RobinRoundDnsDll.dll
- %ProgramFiles%\RunDllInMemory\server.exe
- %ProgramFiles%\RunDllInMemory\ksomt.doc
- '%WINDIR%\server.exe'