Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\v17r29.lnk
- '<SYSTEM32>\rundll32.exe' %TEMP%\92r71v.dss,XL204
- '<SYSTEM32>\rundll32.exe' %ALLUSERSPROFILE%\Application Data\92r71v.dss,XL200
- %ALLUSERSPROFILE%\Application Data\v17r29.bxx
- %TEMP%\92r71v.dss
- %ALLUSERSPROFILE%\Application Data\92r71v.dss
- <SYSTEM32>\PerfStringBackup.TMP
- '20#.#5.133.154':80
- '37.##9.53.244':443