Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'wtfmon' = '%HOMEPATH%\unzipper\wftmon.exe --setstart'
- %HOMEPATH%\unzipper\wftmon.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\getplatnik[1].php
- 'st###lgoto.com':80
- st###lgoto.com/getplatnik.php
- DNS ASK st###lgoto.com
- ClassName: 'Shell_TrayWnd' WindowName: ''