Техническая информация
- '%TEMP%\GtUpdate.exe'
- '<SYSTEM32>\cmd.exe' /c \DelUS.bat
- C:\DelUS.bat
- %TEMP%\nsv2.tmp\SelfDelete.dll
- %TEMP%\GtUpdate.exe
- %TEMP%\nsv2.tmp\SelfDelete.dll
- %TEMP%\Temp.tmp
- %TEMP%\GtUpdate.exe в %TEMP%\Temp.tmp
- 'en###tate.co.kr':80
- en###tate.co.kr/check/GtUpdate/update/inst.php
- en###tate.co.kr/cnt/index.php?pi#################
- DNS ASK en###tate.co.kr