Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '32' = '<SYSTEM32>\kfdk.exe'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{6519DB8A-830C-ABB3-2CAB-93CFF71606AB}] 'StubPath' = '<SYSTEM32>\kfdk.exe'
- %WINDIR%\Explorer.EXE
- msnmsgr.exe
- <SYSTEM32>\kfdk.exe
- 'ka####.zapto.org':82
- DNS ASK ka####.zapto.org