Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'rad' = '%TEMP%\rad.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\rad.exe
- '<SYSTEM32>\systeminfo.exe'
- %TEMP%\rad.exe
- 'ns#.#uplo.com':80
- ns#.#uplo.com/sand/hey.php
- DNS ASK ns#.#uplo.com