Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'winLogon' = 'C:Windows'
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v winLogon /d C:Windows /f
- %WINDIR%\<Имя вируса>.exe
- 'www.lo###stream.com':80
- www.lo###stream.com/Coco.Jr/index.php
- DNS ASK www.lo###stream.com