Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'Update Srv' = '%TEMP%\winservxv\svchost.exe'
- '%TEMP%\winservxv\svchost.exe'
- %TEMP%\lsdzvz.dll
- %TEMP%\winservxv\svchost.exe
- %TEMP%\winservxv\svchost.exe
- %TEMP%\lsdzvz.dll
- 'wa###osting.tk':80
- wa###osting.tk/xyxyx/getcmd.php?id####################
- DNS ASK wa###osting.tk