Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'drivers' = '"<DRIVERS>.exe"'
- '%CommonProgramFiles%\driver.exe'
- '<DRIVERS>.exe'
- %TEMP%\tmpLog
- %CommonProgramFiles%\driver.exe
- <DRIVERS>.exe
- <DRIVERS>.exe
- 'do####d-music.ru':80
- 'wp#d':80
- do####d-music.ru/data/web.txt
- wp#d/wpad.dat
- do####d-music.ru/cm.php
- DNS ASK do####d-music.ru
- DNS ASK wp#d