Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Notification Mapper Print Connect Logon' = '<SYSTEM32>\zvakdgpltxc.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\zvakdgpltxc.exe
- Центр обеспечения безопасности (Security Center)
- '<SYSTEM32>\czqhvipuogz.exe' "<SYSTEM32>\zvakdgpltxc.exe"
- '%TEMP%\gdiljxz5lw8rqsbp.exe' -r 38953 tcp
- '%TEMP%\gdiljxz3r1zrqsboq7omlm.exe'
- '<SYSTEM32>\zvakdgpltxc.exe'
- <SYSTEM32>\hrtcibfztakk\run
- <SYSTEM32>\hrtcibfztakk\rng
- %TEMP%\gdiljxz5lw8rqsbp.exe
- <SYSTEM32>\hrtcibfztakk\cfg
- <SYSTEM32>\czqhvipuogz.exe
- %TEMP%\gdiljxz3r1zrqsboq7omlm.exe
- <SYSTEM32>\hrtcibfztakk\tst
- <SYSTEM32>\zvakdgpltxc.exe
- <SYSTEM32>\hrtcibfztakk\etc
- <SYSTEM32>\czqhvipuogz.exe
- <SYSTEM32>\zvakdgpltxc.exe
- %TEMP%\gdiljxz5lw8rqsbp.exe
- %TEMP%\gdiljxz3r1zrqsboq7omlm.exe
- <DRIVERS>\etc\hosts
- DNS ASK go#####everytime.com
- DNS ASK ta###ark.net
- DNS ASK wa###ews.net
- DNS ASK ja###uter.com
- DNS ASK do####club-grup.com
- DNS ASK el#####arimagine.com
- '23#.#55.255.250':1900