Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%WINDIR%\winrun.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%WINDIR%\system\winlogin.exe'
- %WINDIR%\winrun.exe
- %WINDIR%\system\winlogin.exe
- 'localhost':80
- 12#.0.0.1/priv8/bots.php?na###################
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'