Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'pudevuh' = 'Rundll32.exe "<SYSTEM32>\mafopiw.dll",r'
- '<SYSTEM32>\rundll32.exe' "<SYSTEM32>\mafopiw.dll",r <Полный путь к вирусу>
- <SYSTEM32>\yozuyos.dll
- <SYSTEM32>\mafopiw.dll
- 'an####rplus2011.com':80
- an####rplus2011.com/install/avp.dll?
- DNS ASK my#####virusplus.org
- DNS ASK an####rplus2011.com