Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\MediaeCenterj] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\nbpass] 'ImagePath' = '<DRIVERS>\passthru.sys'
- <SYSTEM32>\svchost.exe -k krnlsrvc
- <SYSTEM32>\Rkmftky.cc3
- <DRIVERS>\passthru.sys
- 'tx####nb.3322.org':8881
- DNS ASK tx####nb.3322.org
- '10.#.1.1':1035