Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] '2220a' = 'rundll32.exe "%APPDATA%\Microsoft\2220a.dll",_220a'
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- %WINDIR%\Explorer.EXE
- opera.exe
- safari.exe
- skype.exe
- chrome.exe
- firefox.exe
- iexplore.exe
- %APPDATA%\Microsoft\2220a.dll
- '84.##4.71.215':8080
- '62.##.184.245':443
- '62.##.184.245':8080
- '87.##6.44.200':8080
- '94.##2.199.78':443
- '67.##3.159.141':8080