Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{5A14C196-3AF1-7EE1-4A5D-3C7A114FF04B}] 'StubPath' = '<SYSTEM32>\winsystem.exe'
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\winsystem.exe
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- 'li###.sytes.net':2000
- DNS ASK li###.sytes.net