Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\Link Bus Manager Shell Fax Firewall Key] 'Start' = '00000002'
- 'C:\uxyxklww\ohoaiffvs.exe' "c:\uxyxklww\yvmeyomg.exe"
- 'C:\uxyxklww\yvmeyomg.exe'
- 'C:\uxyxklww\fvji8cypyat42dhi8e.exe'
- C:\uxyxklww\yvmeyomg.exe
- C:\uxyxklww\ohoaiffvs.exe
- C:\uxyxklww\csz2plgq
- %WINDIR%\uxyxklww\pjumsqehfqy
- C:\uxyxklww\pjumsqehfqy
- C:\uxyxklww\fvji8cypyat42dhi8e.exe
- C:\uxyxklww\ohoaiffvs.exe
- C:\uxyxklww\yvmeyomg.exe
- C:\uxyxklww\fvji8cypyat42dhi8e.exe
- %WINDIR%\uxyxklww\pjumsqehfqy
- DNS ASK ga####instead.net
- DNS ASK be####instead.net
- DNS ASK be####explain.net
- DNS ASK be####bright.net
- DNS ASK ga####explain.net
- DNS ASK tr###inside.net
- DNS ASK st####bright.net
- DNS ASK tr####xplain.net
- DNS ASK dn#.##ftncsi.com
- DNS ASK st####inside.net
- DNS ASK tr###bright.net
- ClassName: 'Shell_TrayWnd' WindowName: ''