Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<Полный путь к вирусу>' = '<Полный путь к вирусу>:*:Enabled:William Hi...
- %TEMP%\is1692802528\261602220.cfg
- %TEMP%\is1692802528\161351444.cfg
- %TEMP%\0001D80B.log
- %TEMP%\0001DF9D.log
- %TEMP%\0001DF9D.log
- %TEMP%\0001D80B.log
- 'eu####.nbeshine.com':80
- 'us####.nbeshine.com':80
- http://eu####.nbeshine.com/Public/Temp/WHCasino.cis
- http://us####.nbeshine.com/Public/Temp/WHCasino.cis
- DNS ASK eu####.nbeshine.com
- DNS ASK us####.nbeshine.com
- ClassName: 'Shell_TrayWnd' WindowName: ''