Техническая информация
- [HKLM\System\CurrentControlSet\Services\Distributed Instrumentation Net.Tcp] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Distributed Instrumentation Net.Tcp] 'ImagePath' = 'C:\miywbhq\aavhvtj.exe'
- 'Distributed Instrumentation Net.Tcp' C:\miywbhq\aavhvtj.exe
- %WINDIR%\miywbhq\ikrv0ojudb
- C:\miywbhq\ikrv0ojudb
- C:\miywbhq\qvsqksmuekbezxmeo.exe
- C:\miywbhq\aavhvtj.exe
- C:\miywbhq\fmpkpgpt.exe
- C:\miywbhq\hqnrrckehc
- C:\miywbhq\aavhvtj.exe
- C:\miywbhq\fmpkpgpt.exe
- %WINDIR%\miywbhq\ikrv0ojudb
- C:\miywbhq\qvsqksmuekbezxmeo.exe
- %WINDIR%\miywbhq\ikrv0ojudb
- DNS ASK se####circle.net
- DNS ASK ag####twheat.net
- DNS ASK do###wheat.net
- DNS ASK ag####tanger.net
- DNS ASK do###anger.net
- DNS ASK ag####talways.net
- DNS ASK do###always.net
- DNS ASK ag####tforest.net
- 'C:\miywbhq\qvsqksmuekbezxmeo.exe'
- 'C:\miywbhq\aavhvtj.exe'
- 'C:\miywbhq\fmpkpgpt.exe' "c:\miywbhq\aavhvtj.exe"