Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'System' = ''
- %TEMP%\1.vbs
- %TEMP%\1.vbs
- 'tu####ollection.com':80
- 'hu###omains.com':443
- http://www.tu####ollection.com/m5/index.php?id############################################
- 'hu###omains.com':443
- DNS ASK tu####ollection.com
- DNS ASK hu###omains.com
- DNS ASK ne#####ent-s2008a.com
- DNS ASK 0b#####or###nmovie.com
- '%WINDIR%\syswow64\cscript.exe' %TEMP%\1.vbs