Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\IRAT] 'Start' = '00000002'
- '<SYSTEM32>\svchost.exe' -k krnlsrvc
- %PROGRAM_FILES%\IRAT\IRAT.rmvb
- %TEMP%\243140.tmp
- %PROGRAM_FILES%\IRAT\IRAT.rmvb
- %TEMP%\243140.tmp
- 'bl######.dx2.yilehost.cn':80
- bl######.dx2.yilehost.cn/ir/ir.txt
- DNS ASK bl######.dx2.yilehost.cn