Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\DNS Defender Topology Parental Health] 'Start' = '00000002'
- 'C:\zlzazlynteubk\qlmvzsrl.exe' "c:\zlzazlynteubk\kjshghox.exe"
- 'C:\zlzazlynteubk\kjshghox.exe'
- 'C:\zlzazlynteubk\uva8bp7zbfesc3vzq.exe'
- C:\zlzazlynteubk\kjshghox.exe
- C:\zlzazlynteubk\qlmvzsrl.exe
- C:\zlzazlynteubk\h9h5fivjdw
- %WINDIR%\zlzazlynteubk\ydg51da
- C:\zlzazlynteubk\ydg51da
- C:\zlzazlynteubk\uva8bp7zbfesc3vzq.exe
- C:\zlzazlynteubk\qlmvzsrl.exe
- C:\zlzazlynteubk\kjshghox.exe
- C:\zlzazlynteubk\uva8bp7zbfesc3vzq.exe
- %WINDIR%\zlzazlynteubk\ydg51da
- DNS ASK ri####thrown.net
- DNS ASK be###gstorm.net
- DNS ASK be####thrown.net
- DNS ASK th###hunger.net
- DNS ASK ch###hunger.net
- DNS ASK ri####training.net
- DNS ASK be####hunger.net
- DNS ASK dn#.##ftncsi.com
- DNS ASK ri###nstorm.net
- DNS ASK be####training.net
- ClassName: 'Shell_TrayWnd' WindowName: ''