Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\pe386] 'Start' = '00000001'
- %WINDIR%\Explorer.EXE
- <SYSTEM32>:lzx32.sys
- '20#.#6.194.158':80
- 20#.#6.194.158/index.php?pa#######
- DNS ASK se####.yahoo.com
- DNS ASK se###h.msn.com
- DNS ASK microsoft.com
- DNS ASK ft#.icq.com