Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'conhost.exe' = '%APPDATA%\Microsoft\conhost.exe'
- 'da##.##romeservices.org':80
- 'wp#d':80
- da##.##romeservices.org/i
- da##.##romeservices.org/c
- wp#d/wpad.dat
- da##.##romeservices.org/o
- DNS ASK da##.##romeservices.org
- DNS ASK wp#d
- DNS ASK www.google.com
- ClassName: 'Indicator' WindowName: '(null)'