Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'FiReWallx' = '%WINDIR%\svihost.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\System.exe
- 'pa#####1994.no-ip.biz':3460
- 'fa###.no-ip.info':1589
- DNS ASK pa#####1994.no-ip.biz
- DNS ASK fa###.no-ip.info