Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] 'AppInit_DLLs' = '0'
- C:\YXgw7pdg0u.dll
- 'gu##oxyz.tk':80
- 'localhost':1037
- http://gu##oxyz.tk/guprodownloaddllbycmdwtf/dllpbvip93847/pAOy5eEJSC.dll
- DNS ASK gu##oxyz.tk
- '<SYSTEM32>\cmd.exe' /c color 07
- '<SYSTEM32>\cmd.exe' /c CLS