Техническая информация
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'shell' = 'explorer.exe, %APPDATA%\hydroquinone.exe'
- %WINDIR%\syswow64\msiexec.exe
- %TEMP%\nsh694e.tmp\system.dll
- %TEMP%\vagabond.dat
- %TEMP%\sarcomas.dll
- %APPDATA%\gg\logs.dat
- %APPDATA%\gg\logs.dat
- DNS ASK pr###ming69.ml
- '%WINDIR%\syswow64\msiexec.exe'