Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'XX' = 'rundll32.exe %TEMP%\xx.dll,XMLResFunc XX 0'
- <SYSTEM32>\rundll32.exe %TEMP%\xx.dll,XMLResFunc XX 0
- %TEMP%\~natty0
- %TEMP%\~natty1
- %TEMP%\cmp.z
- %TEMP%\big.t
- %TEMP%\cfg.ax
- %TEMP%\big.t
- %TEMP%\cmp.z
- 'localhost':80
- localhosthttp://127.0.0.1:80/cxgid/user-4bb09a9c02/33619978/336199780/index.php