Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows Audio Device Graph Isolation' = '%HOMEPATH%\Templates\audiodh.exe'
- %HOMEPATH%\Templates\audiodi.exe
- %HOMEPATH%\Templates\audiodh.exe
- %HOMEPATH%\Templates\audiodi.exe
- %HOMEPATH%\Templates\audiodh.exe
- %HOMEPATH%\Templates\winfire.dat
- %HOMEPATH%\Templates\audiodi.exe
- %HOMEPATH%\Templates\audiodh.exe
- %HOMEPATH%\Templates\winfire.dat
- 'ko##re.in':80
- 'wp#d':80
- wp#d/wpad.dat
- ko##re.in/firesale/conngrab.php
- DNS ASK ko##re.in
- DNS ASK wp#d