Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\*WindowsUpdate*] 'Start' = '00000002'
- C:\OATH.EXE
- <SYSTEM32>\svchost.exe -k netsvcs
- <SYSTEM32>\china.dll
- C:\PEI.TMP
- C:\OATH.EXE
- C:\PEI.TMP
- C:\OATH.EXE
- C:\OATH.EXE
- C:\PEI.TMP
- 'pv##.3322.org':8081
- DNS ASK pv##.3322.org