Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\applicationframehost.url
- '%APPDATA%\l9jmbg.exe'
- %WINDIR%\syswow64\svchost.exe
- %APPDATA%\l9jmbg.exe
- %HOMEPATH%\applicationframehost\applicationframehost.vbs
- %HOMEPATH%\applicationframehost\rtdcpl64.exe
- http://se##-bc.com/royal/helper/gd/zt/cola.exe
- DNS ASK se##-bc.com
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\svchost.exe'