Техническая информация
- [HKLM\System\CurrentControlSet\Services\CNG Player Link Enumerator DCOM] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\CNG Player Link Enumerator DCOM] 'ImagePath' = 'C:\sjwyrdlrobja\eufgfjimanu.exe'
- 'CNG Player Link Enumerator DCOM' C:\sjwyrdlrobja\eufgfjimanu.exe
- %WINDIR%\sjwyrdlrobja\hwrtvhvcg
- C:\sjwyrdlrobja\hwrtvhvcg
- C:\sjwyrdlrobja\uvnqgsqdgbjwjjg8sg.exe
- C:\sjwyrdlrobja\eufgfjimanu.exe
- C:\sjwyrdlrobja\wmfpins.exe
- C:\sjwyrdlrobja\ytnvbjlt
- C:\sjwyrdlrobja\eufgfjimanu.exe
- C:\sjwyrdlrobja\wmfpins.exe
- %WINDIR%\sjwyrdlrobja\hwrtvhvcg
- C:\sjwyrdlrobja\uvnqgsqdgbjwjjg8sg.exe
- %WINDIR%\sjwyrdlrobja\hwrtvhvcg
- DNS ASK gl###manner.net
- DNS ASK an####another.net
- DNS ASK gl####nother.net
- DNS ASK an####business.net
- DNS ASK gl####usiness.net
- DNS ASK an####appear.net
- DNS ASK gl###appear.net
- DNS ASK di####ultmanner.net
- 'C:\sjwyrdlrobja\uvnqgsqdgbjwjjg8sg.exe'
- 'C:\sjwyrdlrobja\eufgfjimanu.exe'
- 'C:\sjwyrdlrobja\wmfpins.exe' "c:\sjwyrdlrobja\eufgfjimanu.exe"