Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'regClient' = '%TEMP%\[Client]\client.exe'
- %TEMP%\windowsupdateapplication.exe
- %TEMP%\[client]\client.exe
- DNS ASK ha######961966.zapto.org
- '%TEMP%\windowsupdateapplication.exe'
- '%WINDIR%\syswow64\cmd.exe'