Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'oktciweb' = '"C:\ProgramData\uqam\qtiquhid.exe"'
- '%WINDIR%\explorer.exe'
- '<SYSTEM32>\attrib.exe'
- <SYSTEM32>\Dwm.exe
- <SYSTEM32>\DllHost.exe
- <SYSTEM32>\attrib.exe
- <SYSTEM32>\taskhost.exe
- C:\ProgramData\uxwxjqow\fxyqizih.dat
- C:\ProgramData\uxwxjqow\udkkanes.dat
- C:\ProgramData\uqam\qtiquhid.exe
- %APPDATA%\Roaming\Microsoft\Crypto\RSA\S-1-5-21-2832440558-3064306045-1455513625-1000\7ee83745df35bad5ccfc8cd8875de253_97c09787-6498-4b10-8f65-9471d842c55e
- C:\ProgramData\uxwxjqow\ekahapaq.dat
- C:\ProgramData\Sun\ekahapaq.bkp
- '20#.#6.232.182':80
- 'fa###ook.com':80
- 'sn###arden.su':443
- 20#.#6.232.182/
- fa###ook.com/
- DNS ASK fa###ook.com
- DNS ASK microsoft.com
- DNS ASK sn###arden.su
- DNS ASK dn#.##ftncsi.com
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'shell_traywnd' WindowName: ''