Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\SNMP Media Fax Program Server] 'Start' = '00000002'
- 'C:\kzntxcgpp\tsjgkkhjywyz.exe' "c:\kzntxcgpp\pnrnuqmgsdvk.exe"
- 'C:\kzntxcgpp\pnrnuqmgsdvk.exe'
- 'C:\kzntxcgpp\ct7y8axpfvwow0s.exe'
- C:\kzntxcgpp\pnrnuqmgsdvk.exe
- C:\kzntxcgpp\tsjgkkhjywyz.exe
- C:\kzntxcgpp\oqrpvqjyi
- %WINDIR%\kzntxcgpp\rvwskypt5
- C:\kzntxcgpp\rvwskypt5
- C:\kzntxcgpp\ct7y8axpfvwow0s.exe
- C:\kzntxcgpp\tsjgkkhjywyz.exe
- C:\kzntxcgpp\pnrnuqmgsdvk.exe
- C:\kzntxcgpp\ct7y8axpfvwow0s.exe
- %WINDIR%\kzntxcgpp\rvwskypt5
- DNS ASK of###guard.net
- DNS ASK al####traight.net
- DNS ASK al###guard.net
- DNS ASK al###fence.net
- DNS ASK of###fence.net
- DNS ASK of####irplane.net
- DNS ASK co####efence.net
- DNS ASK dn#.##ftncsi.com
- DNS ASK of####traight.net
- DNS ASK al####irplane.net
- ClassName: 'Shell_TrayWnd' WindowName: ''