Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\Auto Profile Registry Manager Backup Spooler TP] 'Start' = '00000002'
- 'C:\nvhykqznz\gsifwbb.exe' "c:\nvhykqznz\hngjfzb.exe"
- 'C:\nvhykqznz\hngjfzb.exe'
- 'C:\nvhykqznz\jztxf7khvlhpgfjwy4.exe'
- C:\nvhykqznz\hngjfzb.exe
- C:\nvhykqznz\gsifwbb.exe
- C:\nvhykqznz\p1lbhv
- %WINDIR%\nvhykqznz\wrnaqasdd
- C:\nvhykqznz\wrnaqasdd
- C:\nvhykqznz\jztxf7khvlhpgfjwy4.exe
- C:\nvhykqznz\gsifwbb.exe
- C:\nvhykqznz\hngjfzb.exe
- C:\nvhykqznz\jztxf7khvlhpgfjwy4.exe
- %WINDIR%\nvhykqznz\wrnaqasdd
- DNS ASK ca####nbelieve.net
- DNS ASK la####elieve.net
- DNS ASK la####eceive.net
- DNS ASK la####uarter.net
- DNS ASK ca####nreceive.net
- DNS ASK ca####nbranch.net
- DNS ASK ni####uarter.net
- DNS ASK de####receive.net
- DNS ASK dn#.##ftncsi.com
- DNS ASK la###branch.net
- DNS ASK de####quarter.net
- ClassName: 'Shell_TrayWnd' WindowName: ''