Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '"%APPDATA%\G7MQF5nIwbt61dmO\ZoWvRMinOW6l.exe",explorer.exe'
- %WINDIR%\microsoft.net\framework\v2.0.50727\applaunch.exe
- %APPDATA%\g7mqf5niwbt61dmo\zowvrminow6l.exe
- %APPDATA%\g7mqf5niwbt61dmo\zowvrminow6l.exe
- '46.##5.251.148':37029
- '%WINDIR%\microsoft.net\framework\v2.0.50727\applaunch.exe'