Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\Publication Backup Bus WWAN] 'Start' = '00000002'
- 'C:\maxuixamhuwuln\dgcflvqgyes.exe' "c:\maxuixamhuwuln\tknrqcncs.exe"
- 'C:\maxuixamhuwuln\tknrqcncs.exe'
- 'C:\maxuixamhuwuln\la7zz4f5hpbziwtqk.exe'
- '<SYSTEM32>\wermgr.exe' "-queuereporting_svc" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_tknrqcncs.exe_fa766bcd4aa9edd25731b7bf15aced13e27311_cab_0631fc38"
- C:\maxuixamhuwuln\tknrqcncs.exe
- C:\maxuixamhuwuln\dgcflvqgyes.exe
- C:\maxuixamhuwuln\ou8emsfk
- %WINDIR%\maxuixamhuwuln\kkk2sgtk
- C:\maxuixamhuwuln\kkk2sgtk
- C:\maxuixamhuwuln\la7zz4f5hpbziwtqk.exe
- C:\maxuixamhuwuln\dgcflvqgyes.exe
- C:\maxuixamhuwuln\tknrqcncs.exe
- C:\maxuixamhuwuln\la7zz4f5hpbziwtqk.exe
- %WINDIR%\maxuixamhuwuln\kkk2sgtk
- C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_tknrqcncs.exe_fa766bcd4aa9edd25731b7bf15aced13e27311_cab_0631fc38\Report.wer.tmp в C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_tknrqcncs.exe_fa766bcd4aa9edd25731b7bf15aced13e27311_cab_0631fc38\Report.wer
- DNS ASK he####promise.net
- DNS ASK le####promise.net
- DNS ASK ge####should.net
- DNS ASK he###should.net
- DNS ASK he####opinion.net
- DNS ASK dn#.##ftncsi.com
- DNS ASK le###rshort.net
- DNS ASK le####opinion.net
- DNS ASK he###nshort.net
- ClassName: 'Shell_TrayWnd' WindowName: ''