Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\Tablet Engine HomeGroup Procedure PNRP Registrar] 'Start' = '00000002'
- 'C:\zfihccanggsls\dvpuavnknhoq.exe' "c:\zfihccanggsls\dgeelcrkj.exe"
- 'C:\zfihccanggsls\dgeelcrkj.exe'
- 'C:\zfihccanggsls\af8tchhtv45qaz7.exe'
- C:\zfihccanggsls\dgeelcrkj.exe
- C:\zfihccanggsls\dvpuavnknhoq.exe
- C:\zfihccanggsls\oofxlsjq
- %WINDIR%\zfihccanggsls\ompvzi
- C:\zfihccanggsls\ompvzi
- C:\zfihccanggsls\af8tchhtv45qaz7.exe
- C:\zfihccanggsls\dvpuavnknhoq.exe
- C:\zfihccanggsls\dgeelcrkj.exe
- C:\zfihccanggsls\af8tchhtv45qaz7.exe
- %WINDIR%\zfihccanggsls\ompvzi
- DNS ASK re####eopinion.net
- DNS ASK or####pinion.net
- DNS ASK or####romise.net
- DNS ASK le####should.net
- DNS ASK re####epromise.net
- DNS ASK re####eshort.net
- DNS ASK or###should.net
- DNS ASK ne#####rypromise.net
- DNS ASK dn#.##ftncsi.com
- DNS ASK or###short.net
- DNS ASK re####eshould.net
- ClassName: 'Shell_TrayWnd' WindowName: ''