Техническая информация
- [<HKCU>\software\microsoft\windows\currentversion\run] 'HYAwUAsg.exe' = '%HOMEPATH%\JWMIAUsU\HYAwUAsg.exe'
- [<HKLM>\software\Wow6432Node\microsoft\windows\currentversion\run] 'UqAQogQQ.exe' = '%ALLUSERSPROFILE%\CMAMEoko\UqAQogQQ.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,%ALLUSERSPROFILE%\CMAMEoko\UqAQogQQ.exe,'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = 'userinit.exe,%ALLUSERSPROFILE%\CMAMEoko\UqAQogQQ.exe,'
- %HOMEPATH%\jwmiausu\hyawuasg
- %ALLUSERSPROFILE%\cmameoko\uqaqogqq
- %HOMEPATH%\jwmiausu\hyawuasg.exe
- %ALLUSERSPROFILE%\cmameoko\uqaqogqq.exe
- http://google.com/
- DNS ASK bl##k.io
- DNS ASK google.com
- ClassName: '' WindowName: 'UqAQogQQ.exe'
- ClassName: '' WindowName: 'Microsoft Windows'
- '%HOMEPATH%\jwmiausu\hyawuasg.exe'
- '%ALLUSERSPROFILE%\cmameoko\uqaqogqq.exe'