Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\IP Protection Publication Interactive] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\IP Protection Publication Interactive] 'ImagePath' = 'C:\pvyslrjqv\zfsodlzm.exe'
- 'IP Protection Publication Interactive' C:\pvyslrjqv\zfsodlzm.exe
- %WINDIR%\pvyslrjqv\xmgsbydtrmp
- C:\pvyslrjqv\xmgsbydtrmp
- C:\pvyslrjqv\upojoifhlkglqxm.exe
- C:\pvyslrjqv\zfsodlzm.exe
- C:\pvyslrjqv\pmjuxnsrcy.exe
- C:\pvyslrjqv\zfsodlzm.exe
- C:\pvyslrjqv\pmjuxnsrcy.exe
- %WINDIR%\pvyslrjqv\xmgsbydtrmp
- C:\pvyslrjqv\upojoifhlkglqxm.exe
- %WINDIR%\pvyslrjqv\xmgsbydtrmp
- DNS ASK en####hposition.net
- DNS ASK ei####strike.net
- DNS ASK en####hstrike.net
- DNS ASK ei####partial.net
- DNS ASK en####hpartial.net
- DNS ASK ex####attempt.net
- DNS ASK be####eattempt.net
- DNS ASK ex####square.net
- 'C:\pvyslrjqv\upojoifhlkglqxm.exe'
- 'C:\pvyslrjqv\zfsodlzm.exe'
- 'C:\pvyslrjqv\pmjuxnsrcy.exe' "c:\pvyslrjqv\zfsodlzm.exe"