Техническая информация
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '<SYSTEM32>\winlogin.exe'
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%WINDIR%\winrun.exe'
- 'co####sfelices.com':80
- http://co####sfelices.com/wp-banner.php
- DNS ASK co####sfelices.com