Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Base Socket Class Fax Management CNG' = '%APPDATA%\xwlrbeavn\ycfxoljfm.exe'
- '%APPDATA%\xwlrbeavn\kphbrsxvnxz.exe' "%APPDATA%\xwlrbeavn\ycfxoljfm.exe"
- '%APPDATA%\xwlrbeavn\ycfxoljfm.exe'
- %APPDATA%\xwlrbeavn\ycfxoljfm.uyjzr
- %APPDATA%\xwlrbeavn\kphbrsxvnxz.exe
- %APPDATA%\xwlrbeavn\ycfxoljfm.exe
- %APPDATA%\xwlrbeavn\ycfxoljfm.exe
- 'fa####attempt.net':80
- 'pi####espread.net':80
- fa####attempt.net/index.php?em############################################
- pi####espread.net/index.php?em############################################
- DNS ASK ch####ensquare.net
- DNS ASK fa####square.net
- DNS ASK ch#####nneighbor.net
- DNS ASK fa####attempt.net
- DNS ASK pi####espread.net
- DNS ASK ci####ttespread.net
- DNS ASK ch####enattempt.net
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''