Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\Connect Shadow Support Multimedia Procedure] 'Start' = '00000002'
- 'C:\tmnjmmlxkkw\xanuujnogpmn.exe' "c:\tmnjmmlxkkw\yyzmqowvy.exe"
- 'C:\tmnjmmlxkkw\yyzmqowvy.exe'
- 'C:\tmnjmmlxkkw\ebrwt9h1pqxbkbztwxq9g.exe'
- C:\tmnjmmlxkkw\yyzmqowvy.exe
- C:\tmnjmmlxkkw\xanuujnogpmn.exe
- C:\tmnjmmlxkkw\xftcm1oosj
- %WINDIR%\tmnjmmlxkkw\suiveyv9aj
- C:\tmnjmmlxkkw\suiveyv9aj
- C:\tmnjmmlxkkw\ebrwt9h1pqxbkbztwxq9g.exe
- C:\tmnjmmlxkkw\xanuujnogpmn.exe
- C:\tmnjmmlxkkw\yyzmqowvy.exe
- C:\tmnjmmlxkkw\ebrwt9h1pqxbkbztwxq9g.exe
- %WINDIR%\tmnjmmlxkkw\suiveyv9aj
- DNS ASK tr###inside.net
- DNS ASK st####inside.net
- DNS ASK be####instead.net
- DNS ASK be####explain.net
- DNS ASK ga####instead.net
- DNS ASK tr###bright.net
- DNS ASK st####explain.net
- DNS ASK tr####nstead.net
- DNS ASK dn#.##ftncsi.com
- DNS ASK st####bright.net
- DNS ASK tr####xplain.net
- ClassName: 'Shell_TrayWnd' WindowName: ''