Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\CNG Now Group Connectivity] 'Start' = '00000002'
- 'C:\rkkscyl\lqslriflbqc.exe' "c:\rkkscyl\hvsdsijanrg.exe"
- 'C:\rkkscyl\hvsdsijanrg.exe'
- 'C:\rkkscyl\anp8ti3vutjgxqvbr.exe'
- C:\rkkscyl\hvsdsijanrg.exe
- C:\rkkscyl\lqslriflbqc.exe
- C:\rkkscyl\cubbuo
- %WINDIR%\rkkscyl\xrelhho8ekv
- C:\rkkscyl\xrelhho8ekv
- C:\rkkscyl\anp8ti3vutjgxqvbr.exe
- C:\rkkscyl\lqslriflbqc.exe
- C:\rkkscyl\hvsdsijanrg.exe
- C:\rkkscyl\anp8ti3vutjgxqvbr.exe
- %WINDIR%\rkkscyl\xrelhho8ekv
- DNS ASK do####uarter.net
- DNS ASK ag####tquarter.net
- DNS ASK ni###branch.net
- DNS ASK ni####elieve.net
- DNS ASK de####branch.net
- DNS ASK do####eceive.net
- DNS ASK dn#.##ftncsi.com
- DNS ASK do###branch.net
- DNS ASK ag####tbelieve.net
- DNS ASK ag####treceive.net
- DNS ASK do####elieve.net
- ClassName: 'Shell_TrayWnd' WindowName: ''