Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'Explorer.exe %WINDIR%\winlogon.exe'
- %WINDIR%\winlogon.exe
- %WINDIR%\winlogon.exe
- 'se######atus.elementfx.com':80
- se######atus.elementfx.com/ISPCompany.txt
- DNS ASK se######atus.elementfx.com