Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'rdchelp' = '%WINDIR%\acl6.exe'
- '%WINDIR%\acl6.exe'
- '<SYSTEM32>\wermgr.exe' -queuereporting
- <LS_APPDATA>\Microsoft\Windows\Temporary Internet Files\Content.IE5\6P5SDOMI\txt[1].txt
- %WINDIR%\acl6.exe
- <DRIVERS>\etc\hosts
- 'z-##c7.com':80
- z-##c7.com/txt.txt
- DNS ASK z-##c7.com