Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Service] 'Start' = '00000002'
- '<SYSTEM32>\winr.exe'
- <SYSTEM32>\nrwsers.sys
- <SYSTEM32>\winr.exe
- <SYSTEM32>\srvany.exe
- %TEMP%\E_N4\krnln.fnr
- %TEMP%\E_N4\Exmlrpc.fne
- %TEMP%\E_N4\zlib.dll
- <SYSTEM32>\winr.exe
- 'xu#####g888.vicp.net':8793
- DNS ASK xu#####g888.vicp.net