Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run\] 'AVSoft' = '%PROGRAMDATA%\TNOKSQEBNGQG.exe\TNOKSQEBNGQG.exe'
- <SYSTEM32>\dwm.exe
- <SYSTEM32>\taskhost.exe
- iexplore.exe
- firefox.exe
- %PROGRAMDATA%\tnoksqebngqg.exe\tnoksqebngqg.exe
- '13#.#85.105.93':80
- '%PROGRAMDATA%\tnoksqebngqg.exe\tnoksqebngqg.exe'