Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'lolwut' = '"%PROGRAM_FILES%\lolwut.exe"'
- %PROGRAM_FILES%\lolwut.exe
- %WINDIR%\NOTEPAD.EXE
- %PROGRAM_FILES%\lolwut.exe
- %PROGRAM_FILES%\lolwut.exe
- 'st####ng.zapto.org':1035
- DNS ASK st####ng.zapto.org
- ClassName: 'Indicator' WindowName: ''