Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Winlogon' = '%WINDIR%\winlogon.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Winlogon' = '%WINDIR%\winlogon.exe'
- '%WINDIR%\winlogon.exe'
- '<SYSTEM32>\rundll32.exe' dfdts.dll,DfdGetDefaultPolicyAndSMART
- %APPDATA%\Roaming\FDAAD129-04DF-4089-BB80-174CE725F721\run.dat
- %WINDIR%\winlogon.exe
- '5.##.26.40':7763
- DNS ASK dn#.##ftncsi.com
- ClassName: 'Indicator' WindowName: '(null)'