Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\Event Function Browser Reporting Class WMI] 'Start' = '00000002'
- 'C:\hcyfysuesihiym\nllpilg.exe' "c:\hcyfysuesihiym\pfklxqvegm.exe"
- 'C:\hcyfysuesihiym\pfklxqvegm.exe'
- 'C:\hcyfysuesihiym\ur8cdgrdxd1eukjhpl.exe'
- C:\hcyfysuesihiym\pfklxqvegm.exe
- C:\hcyfysuesihiym\nllpilg.exe
- C:\hcyfysuesihiym\vshqzldilazd
- %WINDIR%\hcyfysuesihiym\ldbwc3z
- C:\hcyfysuesihiym\ldbwc3z
- C:\hcyfysuesihiym\ur8cdgrdxd1eukjhpl.exe
- C:\hcyfysuesihiym\nllpilg.exe
- C:\hcyfysuesihiym\pfklxqvegm.exe
- C:\hcyfysuesihiym\ur8cdgrdxd1eukjhpl.exe
- %WINDIR%\hcyfysuesihiym\ldbwc3z
- DNS ASK se####bottle.net
- DNS ASK qu###bottle.net
- DNS ASK qu###divide.net
- DNS ASK ag####tmanner.net
- DNS ASK se####divide.net
- DNS ASK dn#.##ftncsi.com
- DNS ASK qu###stream.net
- DNS ASK se####stream.net
- DNS ASK se####nothing.net
- DNS ASK qu####othing.net
- ClassName: 'Shell_TrayWnd' WindowName: ''