Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'winlogon' = '"%TEMP%\scvhost.exe"'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '{{GguggugUFufufGuigffz}}' = '"%TEMP%\WinLogon"'
- %TEMP%\scvhost.exe
- %TEMP%\WinLogon
- %TEMP%\scvhost.exe
- 'ir#.##nupdates.nl':2109
- DNS ASK ir#.##nupdates.nl