Техническая информация
- [<HKCU>\software\microsoft\windows\currentversion\run] 'eokswQYI.exe' = '%HOMEPATH%\PcAwUcEk\eokswQYI.exe'
- [<HKLM>\software\Wow6432Node\microsoft\windows\currentversion\run] 'YSggccAw.exe' = '%ALLUSERSPROFILE%\OeIwsgUg\YSggccAw.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,%ALLUSERSPROFILE%\OeIwsgUg\YSggccAw.exe,'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = 'userinit.exe,%ALLUSERSPROFILE%\OeIwsgUg\YSggccAw.exe,'
- %HOMEPATH%\pcawucek\eokswqyi
- %ALLUSERSPROFILE%\oeiwsgug\ysggccaw
- %HOMEPATH%\pcawucek\eokswqyi.exe
- %ALLUSERSPROFILE%\oeiwsgug\ysggccaw.exe
- %WINDIR%\syswow64\config\systemprofile\pcawucek\eokswqyi
- <Текущая директория>\dkwm.exe
- <Текущая директория>\dkwm.exe
- http://google.com/
- DNS ASK bl##k.io
- DNS ASK google.com
- '%HOMEPATH%\pcawucek\eokswqyi.exe'
- '%ALLUSERSPROFILE%\oeiwsgug\ysggccaw.exe'