Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'System Update' = '%WINDIR%\svhost.exe'
- %WINDIR%\svhost.exe
- '63.##6.108.2':80
- 63.##6.108.2/images/vqadmin/.manager/infect.php
- ClassName: '' WindowName: ''
- ClassName: 'NDDEAgnt' WindowName: 'NetDDE Agent'