Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] 'Microsoft Svchost local services' = 'nodkrn23.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Svchost local services' = 'nodkrn23.exe'
- %WINDIR%\nodkrn23.exe 300 "<Полный путь к вирусу>"
- %WINDIR%\nodkrn23.exe
- %WINDIR%\nodkrn23.exe
- '25#.#55.255.255':6667
- 'ir#.#-warez.net':6667
- DNS ASK ir#.#-warez.net