Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'CSJFireRed' = '"%TEMP%\Userint.exe"'
- %TEMP%\svch0st.exe
- %TEMP%\Userint.exe
- %TEMP%\Userint.exe
- '12#.#.247.165':1997
- 'http://12#.0.0.1/get.asp':80
- http://12#.0.0.1/get.aspGet.asp
- DNS ASK http://12#.0.0.1/get.asp