Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\AMService] 'Start' = '00000002'
- <SYSTEM32>\<Имя вируса>.exe
- 'www.sy##em.com':80
- 'www.tr##run.com':80
- www.sy##em.com/CallBack/SomeScripts/mgsNewPeer.php
- www.tr##run.com/CallBack/SomeScripts/mgsNewPeer.php
- DNS ASK www.sy##em.com
- DNS ASK www.tr##run.com