Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\Portable Coordinator Network UserMode] 'Start' = '00000002'
- 'C:\unaiqapx\yynmjksy.exe' "c:\unaiqapx\ciijoedlk.exe"
- 'C:\unaiqapx\ciijoedlk.exe'
- 'C:\unaiqapx\jypx8ddvtonzzecjivooc.exe'
- C:\unaiqapx\ciijoedlk.exe
- C:\unaiqapx\yynmjksy.exe
- C:\unaiqapx\gilhvy6fn
- %WINDIR%\unaiqapx\tqmmfuelcjxj
- C:\unaiqapx\tqmmfuelcjxj
- C:\unaiqapx\jypx8ddvtonzzecjivooc.exe
- C:\unaiqapx\yynmjksy.exe
- C:\unaiqapx\ciijoedlk.exe
- C:\unaiqapx\jypx8ddvtonzzecjivooc.exe
- %WINDIR%\unaiqapx\tqmmfuelcjxj
- DNS ASK re####eopinion.net
- DNS ASK or####pinion.net
- DNS ASK or####romise.net
- DNS ASK le####should.net
- DNS ASK re####epromise.net
- DNS ASK re####eshort.net
- DNS ASK or###should.net
- DNS ASK ne#####rypromise.net
- DNS ASK dn#.##ftncsi.com
- DNS ASK or###short.net
- DNS ASK re####eshould.net
- ClassName: 'Shell_TrayWnd' WindowName: ''