Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '<Полный путь к вирусу>'
- 'www.pl##k.com':80
- 'wc#####pp.marketddy.com':80
- 'fa#######ssip.pchome-shop.com':80
- www.pl##k.com/c1011585
- wc#####pp.marketddy.com/zK52Ann1nrTQZlaYB*xIdq
- fa#######ssip.pchome-shop.com/zK52Ann1nrTQZlaYB*xIdq
- wc#####pp.marketddy.com/zK52Ann1nrTQZlaYB*xIdq
- fa#######ssip.pchome-shop.com/zK52Ann1nrTQZlaYB*xIdq
- DNS ASK www.pl##k.com
- DNS ASK wc#####pp.marketddy.com
- DNS ASK fa#######ssip.pchome-shop.com