Техническая информация
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'shell' = 'explorer.exe,%APPDATA%\data.dat'
- %WINDIR%\explorer.exe
- %WINDIR%\syswow64\svchost.exe
- %APPDATA%\data.dat
- %APPDATA%\settings.ini
- DNS ASK bw##b.net
- DNS ASK vm##z.su
- '%WINDIR%\syswow64\svchost.exe'
- '%WINDIR%\syswow64\ctfmon.exe'