Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Microsoft' = '%WINDIR%\SccHoster32.exe'
- '%WINDIR%\SccHoster32.exe' "<Полный путь к вирусу>"
- <SYSTEM32>\svchost.exe
- %WINDIR%\SccHoster32.exe
- %WINDIR%\SccHoster32.exe
- 'pa####k.2mydns.com':113
- DNS ASK pa####k.2mydns.com
- ClassName: 'Indicator' WindowName: ''