Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'shell' = 'explorer.exe, %APPDATA%\aa7d7925\newdev.exe'
- %WINDIR%\syswow64\msiexec.exe
- %TEMP%\nsd21ba.tmp
- %TEMP%\nss21ca.tmp\system.dll
- %TEMP%\girdle.dat
- %TEMP%\pedipalps.dll
- %APPDATA%\aa7d7925\newdev.exe
- DNS ASK gr###pool.site
- '%WINDIR%\syswow64\msiexec.exe'