Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'winlogon' = '%APPDATA%\Installation\winlogon.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\WinEx.exe
- %APPDATA%\Installation\usft_ext.dll
- %APPDATA%\Installation\winlogon.exe
- %APPDATA%\Installation\phatk.ptx
- %APPDATA%\Installation\taskmanager.exe
- %APPDATA%\Installation\miner.dll
- ClassName: 'Indicator' WindowName: ''