Техническая информация
- %WINDIR%\tasks\su.dll
- '<SYSTEM32>\rundll32.exe' %WINDIR%\Tasks\su.dll, PluginInit
- '66.##0.66.167':80
- 'er###adifa.com':80
- http://66.##0.66.167/su.dll
- http://er###adifa.com/
- DNS ASK er###adifa.com
- '<SYSTEM32>\rundll32.exe' %WINDIR%\Tasks\su.dll, PluginInit' (со скрытым окном)