Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'run' = ''
- [<HKLM>\SOFTWARE\Classes\exefile\shell\open\command] '' = '"%1" %*'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'IECheck' = '<SYSTEM32>\sslenc.exe'
- %WINDIR%\msi486.dll
- <SYSTEM32>\sslenc.exe
- 'l.#et':6667
- 'ma####.sytes.net':6667
- '25#.#55.255.255':6667
- 'ir#.dal.net':6667
- DNS ASK l.#et
- DNS ASK ma####.sytes.net
- DNS ASK br#####0rm.sytes.net
- DNS ASK ir#.dal.net