Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'java' = '<SYSTEM32>\isass.exe'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{B28B3F78-0D3A-7849-FDFD-606D3C78EF9B}] 'StubPath' = '<SYSTEM32>\isass.exe'
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\isass.exe
- <SYSTEM32>\71okj.JPG
- 'sa####ad.zapto.org':1081
- DNS ASK sa####ad.zapto.org