Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = ''
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\Userinit.exe'
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\wlrmdr.exe
- %WINDIR%\syswow64\drivers\usbinite.sys
- '34.##9.100.209':443