Техническая информация
- %APPDATA%\Microsoft\windows\Start Menu\programs\startup\iwlq3hb.lnk
- %ProgramFiles%\bh3qlwi.plz
- %ProgramFiles%\iwlq3hb.pff
- '64.##0.167.162':80
- '37.##9.53.199':80
- '64.##0.167.162':443
- '34.##9.100.209':443
- '%WINDIR%\syswow64\rundll32.exe' C:\PROGRA~3\bh3qlwi.plz,GL300
- '%WINDIR%\syswow64\regedit.exe' -s C:\PROGRA~3\iwlq3hb.reg