Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '"%APPDATA%\8w0luN1psq26Dx6N\QIJL3iHvwkTF.exe",explorer.exe'
- %TEMP%\23D3E.dmp
- %TEMP%\dw.log
- %APPDATA%\8w0luN1psq26Dx6N\QIJL3iHvwkTF.exe
- %APPDATA%\8w0luN1psq26Dx6N\QIJL3iHvwkTF.exe
- ClassName: 'Shell_TrayWnd' WindowName: ''