Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Time Manager' = '%PROGRAMDATA%\TimeManager.exe'
- <SYSTEM32>\svchost.exe
- %PROGRAMDATA%\timemanager.exe
- %PROGRAMDATA%\time manager\auto_miner64
- %PROGRAMDATA%\timemanager.exe
- %PROGRAMDATA%\time manager\auto_miner64
- 'lk###fdsa2.ru':25998
- 'lk###fdsa2.ru':31258
- 'as###hjkl0.com':53021
- DNS ASK google-public-dns-b.google.com
- DNS ASK lk###fdsa2.ru
- DNS ASK as###hjkl0.com
- '<SYSTEM32>\svchost.exe'