Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\] 'Userinit' = '<SYSTEM32>\userinit.exe,C:\Arquivos de programas\857LkaFK.exe'
- %WINDIR%\window.exe
- 'sp######2000.com.sapo.pt':80
- '<LOCALNET>.19.9':80
- DNS ASK sp######2000.com.sapo.pt
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\window.exe'