Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Taskman' = '%HOMEPATH%\xcqzq.exe'
- %WINDIR%\syswow64\svchost.exe
- %HOMEPATH%\xcqzq.exe
- %HOMEPATH%\xcqzq.exe
- DNS ASK sp##.#ollective.su
- DNS ASK jo####.upward.su
- DNS ASK ki#.#nvelope.su
- ClassName: 'Subyism' WindowName: 'Irooua Ada Oax Y'
- '%WINDIR%\syswow64\svchost.exe'