Техническая информация
- [HKLM\System\CurrentControlSet\Services\Launcher Registry Transaction] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Launcher Registry Transaction] 'ImagePath' = 'C:\wfocdtxpayu\mozfoztr.exe'
- 'Launcher Registry Transaction' C:\wfocdtxpayu\mozfoztr.exe
- %WINDIR%\wfocdtxpayu\a7hoqqlr
- C:\wfocdtxpayu\a7hoqqlr
- C:\wfocdtxpayu\ildyduoodpoeqsnprwq.exe
- C:\wfocdtxpayu\mozfoztr.exe
- C:\wfocdtxpayu\yelzvydykl.exe
- C:\wfocdtxpayu\mozfoztr.exe
- C:\wfocdtxpayu\yelzvydykl.exe
- %WINDIR%\wfocdtxpayu\a7hoqqlr
- C:\wfocdtxpayu\ildyduoodpoeqsnprwq.exe
- %WINDIR%\wfocdtxpayu\a7hoqqlr
- '34.##9.100.209':443
- DNS ASK ma####etrain.net
- DNS ASK pe#####lectricity.net
- DNS ASK ma#####electricity.net
- DNS ASK pe####delight.net
- DNS ASK ma####edelight.net
- DNS ASK su####borrow.net
- DNS ASK fo####nborrow.net
- 'C:\wfocdtxpayu\ildyduoodpoeqsnprwq.exe'
- 'C:\wfocdtxpayu\mozfoztr.exe'
- 'C:\wfocdtxpayu\yelzvydykl.exe' "c:\wfocdtxpayu\mozfoztr.exe"