Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\RemoteServer] 'Start' = '00000002'
- <SYSTEM32>\rundll32.exe "%TEMP%\RemoteServer49.dll" InstallService
- %TEMP%\RemoteServer49.dll
- %TEMP%\Tempfl.txt
- %TEMP%\Tempfl.txt
- 'cn#.#zads.cn':802
- DNS ASK cn#.#zads.cn