Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{6F2E537A-82CA-EC1F-F141-DDECEC068177}] 'StubPath' = '<Полный путь к вирусу>'
- %WINDIR%\Explorer.EXE
- 'www.tk###jee.org':3820
- 'www.ts##esk.org':3351
- DNS ASK www.tk###jee.org
- DNS ASK www.ts##esk.org