Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Taskman' = '%APPDATA%\efnlz.exe'
- %WINDIR%\Explorer.EXE
- %APPDATA%\efnlz.exe
- %APPDATA%\efnlz.exe
- DNS ASK ov###oading.us
- DNS ASK go###eupdate.in
- DNS ASK mi####oftgroups.com
- 'mi####oftgroups.com':444
- 'ov###oading.us':444
- ClassName: 'Progman' WindowName: ''