Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'windres' = '<SYSTEM32>:scschost.exe'
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -nohome
- %WINDIR%\Explorer.EXE
- <SYSTEM32>:scschost.exe
- 'lq####.kicks-ass.net':3460
- 'do######ng.kicks-ass.net':3460
- DNS ASK lq####.kicks-ass.net
- DNS ASK do######ng.kicks-ass.net