Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\Task Routing Procedure UserMode WWAN IPsec] 'Start' = '00000002'
- 'C:\cemoizoikn\caduzpwrl.exe' "c:\cemoizoikn\lcubroosm.exe"
- 'C:\cemoizoikn\lcubroosm.exe'
- 'C:\cemoizoikn\ym8u47koeijn5rxuh.exe'
- C:\cemoizoikn\lcubroosm.exe
- C:\cemoizoikn\caduzpwrl.exe
- C:\cemoizoikn\jjgoxjdr
- %WINDIR%\cemoizoikn\pjokhsp
- C:\cemoizoikn\pjokhsp
- C:\cemoizoikn\ym8u47koeijn5rxuh.exe
- C:\cemoizoikn\caduzpwrl.exe
- C:\cemoizoikn\lcubroosm.exe
- C:\cemoizoikn\ym8u47koeijn5rxuh.exe
- %WINDIR%\cemoizoikn\pjokhsp
- DNS ASK jo####yhowever.net
- DNS ASK hu####dperiod.net
- DNS ASK hu####dhowever.net
- DNS ASK li####choose.net
- DNS ASK de####ychoose.net
- DNS ASK jo####yperiod.net
- DNS ASK hu####dchoose.net
- DNS ASK jo####ychoose.net
- DNS ASK dn#.##ftncsi.com
- DNS ASK hu####dalthough.net
- DNS ASK jo####yalthough.net
- ClassName: 'Shell_TrayWnd' WindowName: ''