Техническая информация
- %PROGRAMDATA%\gugbqw.dll
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- DNS ASK microsoft.com
- '<SYSTEM32>\cmd.exe' /c kokoko%random%kokkook & R^eGsv^r32 -s %PROGRAMDATA%\gugbqW.dll' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c kokoko%random%kokkook & R^eGsv^r32 -s %PROGRAMDATA%\gugbqW.dll
- '<SYSTEM32>\regsvr32.exe' -s %PROGRAMDATA%\gugbqW.dll