Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '863196' = '<SYSTEM32>\msokma.exe'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{0875E79C-1AA2-ACAC-1598-FAF10C7B323E}] 'StubPath' = '<SYSTEM32>\msokma.exe'
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\msokma.exe
- 'fi##an.com':443
- 'ta##8.com':443
- DNS ASK fi##an.com
- DNS ASK ta##8.com