Техническая информация
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Windows Update Check' = '<SYSTEM32>\syslodr.exe'
- %WINDIR%\syswow64\syslodr.exe
- %TEMP%\~cdsf3kj09u.tmp
- 'ca##car.org':80
- http://ca##car.org/loader/timeout.txt
- http://ca##car.org/loader/count.php
- http://ca##car.org/loader/hosts.txt
- http://ca##car.org/loader/url.txt
- DNS ASK ca##car.org