Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\CyService] 'Start' = '00000002'
- '%ALLUSERSPROFILE%\realupdate.exe' *<Полный путь к вирусу>
- '<SYSTEM32>\svchost.exe' -k netsvcs
- <SYSTEM32>\cydll.dll
- %ALLUSERSPROFILE%\realupdate.exe
- 'ft#.###hone.ocry.com':80
- http://ft#.###hone.ocry.com/171687
- http://ft#.###hone.ocry.com/149140
- DNS ASK ft#.###hone.ocry.com