Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'kernel32' = '<SYSTEM32>\win64.exe'
- %TEMP%\aut1.tmp
- %TEMP%\zychqsi
- <SYSTEM32>\win64.exe
- %TEMP%\aut1.tmp
- %TEMP%\zychqsi
- 'ph##tu.net':80
- http://ph##tu.net/zrget.php?re#######################
- http://ph##tu.net/command.txt
- DNS ASK ph##tu.net