Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '"%APPDATA%\sGFB5DAuAStB2W3e\AjZCQ1l8diaI.exe",explorer.exe'
- %APPDATA%\Imminent\Logs\01-01-2015
- %APPDATA%\sGFB5DAuAStB2W3e\AjZCQ1l8diaI.exe
- %APPDATA%\sGFB5DAuAStB2W3e\AjZCQ1l8diaI.exe
- '91.##6.116.117':3127