Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'explorer' = '<SYSTEM32>\scif\explorer.exe'
- <SYSTEM32>\scif\svchost.exe
- <SYSTEM32>\scif\explorer.exe
- <SYSTEM32>\scif\MSWINSCK.OCX
- <SYSTEM32>\scif\svchost.exe
- <SYSTEM32>\scif\MSINET.OCX
- %TEMP%\nsd2.tmp
- <SYSTEM32>\scif\explorer.exe
- 'ba####.forestnet.org':6667
- 'eu.##dernet.org':6667
- 'ir#.##restnet.org':6667
- '19#.#09.20.90':6667
- 'bu#######.ro.eu.undernet.org':6667
- 'me##.##.us.undernet.org':6667
- DNS ASK He######.FI.EU.Undernet.org
- DNS ASK Lo#####.UK.EU.Undernet.Org
- DNS ASK os###.##.eu.undernet.org
- DNS ASK ir#.##restnet.org
- DNS ASK me##.##.us.undernet.org
- DNS ASK bu#######.ro.eu.undernet.org
- DNS ASK eu.##dernet.org
- DNS ASK ba####.forestnet.org