Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\nethost] 'Start' = '00000000'
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\6YQRA29M\getcfg[1].htm
- <SYSTEM32>\DLL1.tmp
- <DRIVERS>\nethost.sys
- <SYSTEM32>\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\6YQRA29M\getcfg[1].htm
- 'nd####433.mcdir.ru':80
- '77####2ll.mcdir.ru':80
- 'la###to.nut.cc':80
- nd####433.mcdir.ru/tsto2/getcfg.php
- 77####2ll.mcdir.ru/tsto2/getcfg.php
- la###to.nut.cc/boorda/getcfg.php
- DNS ASK nd####433.mcdir.ru
- DNS ASK 77####2ll.mcdir.ru
- DNS ASK la###to.nut.cc