Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'IsClosed' = '"%LOCALAPPDATA%\IsFaulted\6m9Baf8F1JklHMHThJ\IsClosed.exe"'
- %WINDIR%\microsoft.net\framework\v4.0.30319\aspnet_wp.exe
- %LOCALAPPDATA%\isfaulted\6m9baf8f1jklhmhthj\isclosed.exe