Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Network Adapter Monitor] 'Start' = '00000002'
- <SYSTEM32>\msggblkw.exe /service
- <SYSTEM32>\msggblkw.exe
- 'lu###strike.cc':80
- '20#.#6.232.182':80
- lu###strike.cc/client/start.php
- DNS ASK lu###strike.cc
- DNS ASK www.microsoft.com