Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\Tablet Sharing Netlogon Detection] 'Start' = '00000002'
- 'C:\kcmrmgoljh\izeawdhxp.exe' "c:\kcmrmgoljh\csgdutnipkka.exe"
- 'C:\kcmrmgoljh\csgdutnipkka.exe'
- 'C:\kcmrmgoljh\omemf3u59vfkcnm0js.exe'
- C:\kcmrmgoljh\csgdutnipkka.exe
- C:\kcmrmgoljh\izeawdhxp.exe
- C:\kcmrmgoljh\grvvrafqsvyg
- %WINDIR%\kcmrmgoljh\wcoeczrs5k
- C:\kcmrmgoljh\wcoeczrs5k
- C:\kcmrmgoljh\omemf3u59vfkcnm0js.exe
- C:\kcmrmgoljh\izeawdhxp.exe
- C:\kcmrmgoljh\csgdutnipkka.exe
- C:\kcmrmgoljh\omemf3u59vfkcnm0js.exe
- %WINDIR%\kcmrmgoljh\wcoeczrs5k
- DNS ASK ch####uestion.net
- DNS ASK th###while.net
- DNS ASK th####uestion.net
- DNS ASK th####herefore.net
- DNS ASK ch####herefore.net
- DNS ASK ch###school.net
- DNS ASK be####therefore.net
- DNS ASK dn#.##ftncsi.com
- DNS ASK ch###while.net
- DNS ASK th###school.net
- ClassName: 'Shell_TrayWnd' WindowName: ''