Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Driver Card Initiator Tools Isolation' = 'C:\womkximjdm\doxnxkindqv.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Topology PNRP Shadow AutoConnect] 'ImagePath' = 'C:\womkximjdm\doxnxkindqv.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Topology PNRP Shadow AutoConnect] 'Start' = '00000002'
- C:\womkximjdm\doxnxkindqv.exe
- C:\womkximjdm\kpjpcexim.exe
- C:\womkximjdm\tfq7iod
- %WINDIR%\womkximjdm\jzwldr7sn
- C:\womkximjdm\jzwldr7sn
- C:\womkximjdm\ou54u2pu5kkgamjznta.exe
- C:\womkximjdm\kpjpcexim.exe
- C:\womkximjdm\doxnxkindqv.exe
- C:\womkximjdm\ou54u2pu5kkgamjznta.exe
- %WINDIR%\womkximjdm\jzwldr7sn
- %WINDIR%\womkximjdm\jzwldr7sn
- 'wh####rgeneral.net':80
- http://wh####rgeneral.net/index.php
- DNS ASK ri####eneral.net
- DNS ASK wh####rgeneral.net
- 'C:\womkximjdm\kpjpcexim.exe' "c:\womkximjdm\doxnxkindqv.exe"
- 'C:\womkximjdm\doxnxkindqv.exe'
- 'C:\womkximjdm\ou54u2pu5kkgamjznta.exe'