Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\wstimesvc] 'Start' = '00000002'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\ud.bat
- '<SYSTEM32>\svchost.exe' -k netsvcs
- %WINDIR%\Temp\029666E0.TMP
- %TEMP%\ud.bat
- <SYSTEM32>\wstimesvc.dll
- 'ga###amu.co.kr':80
- '31####tion.co.kr':80
- ga###amu.co.kr/gagunamu/wizboard/skin/bbq/layout.php
- 31####tion.co.kr/wizboard/skin/bbq/layout.php
- DNS ASK ga###amu.co.kr
- DNS ASK 31####tion.co.kr