Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'winamp' = '%WINDIR%\services.exe'
- %TEMP%\rarsfx0\mswinsck.ocx
- %TEMP%\rarsfx0\svchost.exe
- %WINDIR%\services.exe
- %WINDIR%\mswinsck.ocx
- %WINDIR%\mswinsck.ocx
- 'ir#.dal.net':6667
- 'ir#.dal.net':6667
- DNS ASK ir#.dal.net
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\rarsfx0\svchost.exe'