Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Client Windows Extender Publication Detection' = '%HOMEPATH%\Local Settings\Application Data\knselrnvnbgzwx\jkwnklvqqvxx.exe'
- %HOMEPATH%\local settings\application data\knselrnvnbgzwx\jkwnklvqqvxx.exe
- %HOMEPATH%\local settings\application data\knselrnvnbgzwx\brquddzfexz.exe
- %HOMEPATH%\local settings\application data\knselrnvnbgzwx\jkwnklvqqvxx.kvzv4
- %HOMEPATH%\local settings\application data\knselrnvnbgzwx\jkwnklvqqvxx.exe
- %HOMEPATH%\local settings\application data\knselrnvnbgzwx\brquddzfexz.exe
- DNS ASK cl####nclude.net
- DNS ASK th###north.net
- DNS ASK cl###north.net
- DNS ASK th###branch.net
- DNS ASK pr####tbranch.net
- DNS ASK th####elieve.net
- DNS ASK pr####tbelieve.net
- DNS ASK th####eceive.net
- '%HOMEPATH%\local settings\application data\knselrnvnbgzwx\jkwnklvqqvxx.exe'
- '%HOMEPATH%\local settings\application data\knselrnvnbgzwx\brquddzfexz.exe' "%HOMEPATH%\Local Settings\Application Data\knselrnvnbgzwx\jkwnklvqqvxx.exe"