Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Skype' = ''
- <SYSTEM32>\taskhost.exe
- iexplore.exe
- firefox.exe
- %TEMP%\fkdjsadasd.ico
- 'localhost':57976
- '%WINDIR%\syswow64\cmd.exe' /c %WINDIR%\SysNative\vssadmin.exe delete shadows /all /quiet