Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\Workstation Office Source Cache Redirector] 'Start' = '00000002'
- 'C:\sjdxxwmxqubfqb\mnuehlqhhn.exe' "c:\sjdxxwmxqubfqb\owzduyqh.exe"
- 'C:\sjdxxwmxqubfqb\owzduyqh.exe'
- 'C:\sjdxxwmxqubfqb\gh8crcnfqsecjtiw.exe'
- C:\sjdxxwmxqubfqb\owzduyqh.exe
- C:\sjdxxwmxqubfqb\mnuehlqhhn.exe
- C:\sjdxxwmxqubfqb\ygnetid
- %WINDIR%\sjdxxwmxqubfqb\cxtexcz8k
- C:\sjdxxwmxqubfqb\cxtexcz8k
- C:\sjdxxwmxqubfqb\gh8crcnfqsecjtiw.exe
- C:\sjdxxwmxqubfqb\mnuehlqhhn.exe
- C:\sjdxxwmxqubfqb\owzduyqh.exe
- C:\sjdxxwmxqubfqb\gh8crcnfqsecjtiw.exe
- %WINDIR%\sjdxxwmxqubfqb\cxtexcz8k
- DNS ASK in####sebuilt.net
- DNS ASK fo###tbuilt.net
- DNS ASK fo###tcarry.net
- DNS ASK wo###father.net
- DNS ASK in####secarry.net
- DNS ASK in####sefather.net
- DNS ASK fo####father.net
- DNS ASK dn#.##ftncsi.com
- DNS ASK in####seapple.net
- DNS ASK fo###tapple.net
- ClassName: 'Shell_TrayWnd' WindowName: ''