Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\zsxkmaqakp] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\zsxkmaqakp] 'ImagePath' = '%TEMP%\iacsaa.exe -svc'
- 'zsxkmaqakp' %TEMP%\iacsaa.exe -svc
- %TEMP%\iacsaa.exe
- 'ne####k.emloud.com':80
- http://ne####k.emloud.com/webyx/iLog.php?dl##########################
- DNS ASK ne####k.emloud.com
- '%TEMP%\iacsaa.exe' -svc