Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Card Filtering Credential Alerts Browser' = '%APPDATA%\Roaming\hyrkcxmewhqt\lxalbjqwmzp.exe'
- '%APPDATA%\Roaming\hyrkcxmewhqt\ajvgzmyw.exe' "%APPDATA%\Roaming\hyrkcxmewhqt\lxalbjqwmzp.exe"
- '%APPDATA%\Roaming\hyrkcxmewhqt\lxalbjqwmzp.exe'
- %APPDATA%\Roaming\hyrkcxmewhqt\lxalbjqwmzp.m6y
- %APPDATA%\Roaming\hyrkcxmewhqt\ajvgzmyw.exe
- %APPDATA%\Roaming\hyrkcxmewhqt\lxalbjqwmzp.exe
- %APPDATA%\Roaming\hyrkcxmewhqt\lxalbjqwmzp.exe
- DNS ASK wh####rpromise.net
- DNS ASK ri####pinion.net
- DNS ASK ri####romise.net
- DNS ASK th####should.net
- DNS ASK fi####should.net
- DNS ASK wh####ropinion.net
- DNS ASK ri###should.net
- DNS ASK wh####rshould.net
- DNS ASK dn#.##ftncsi.com
- DNS ASK ri###short.net
- DNS ASK wh####rshort.net
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''