Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\Biometric Controls Defragmenter Player] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Biometric Controls Defragmenter Player] 'ImagePath' = 'C:\xdduaboaxzj\eztklcbqxaw.exe'
- 'Biometric Controls Defragmenter Player' C:\xdduaboaxzj\eztklcbqxaw.exe
- %WINDIR%\xdduaboaxzj\bo4ulyx2tu
- C:\xdduaboaxzj\bo4ulyx2tu
- C:\xdduaboaxzj\eqjwznw8sukoxnti.exe
- C:\xdduaboaxzj\eztklcbqxaw.exe
- C:\xdduaboaxzj\uvdvjokvvh.exe
- C:\xdduaboaxzj\k9ctojwjlz
- C:\xdduaboaxzj\eztklcbqxaw.exe
- C:\xdduaboaxzj\uvdvjokvvh.exe
- %WINDIR%\xdduaboaxzj\bo4ulyx2tu
- C:\xdduaboaxzj\eqjwznw8sukoxnti.exe
- %WINDIR%\xdduaboaxzj\bo4ulyx2tu
- DNS ASK ex####condition.net
- DNS ASK be#####condition.net
- DNS ASK pe####nation.net
- DNS ASK ma####enation.net
- DNS ASK pe####soldier.net
- DNS ASK ma####esoldier.net
- DNS ASK pe####please.net
- DNS ASK ma####eplease.net
- DNS ASK pe####condition.net
- 'C:\xdduaboaxzj\eqjwznw8sukoxnti.exe'
- 'C:\xdduaboaxzj\eztklcbqxaw.exe'
- 'C:\xdduaboaxzj\uvdvjokvvh.exe' "c:\xdduaboaxzj\eztklcbqxaw.exe"