Техническая информация
- [HKLM\System\CurrentControlSet\Services\Installer Hardware Remote SNMP Fax] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Installer Hardware Remote SNMP Fax] 'ImagePath' = 'C:\gddgapmr\tjumzslvg.exe'
- 'Installer Hardware Remote SNMP Fax' C:\gddgapmr\tjumzslvg.exe
- %WINDIR%\gddgapmr\abdsmd
- C:\gddgapmr\abdsmd
- C:\gddgapmr\qcmaddpojqpqpkwbpekg.exe
- C:\gddgapmr\tjumzslvg.exe
- C:\gddgapmr\lcscebyvaqw.exe
- C:\gddgapmr\tjumzslvg.exe
- C:\gddgapmr\lcscebyvaqw.exe
- %WINDIR%\gddgapmr\abdsmd
- C:\gddgapmr\qcmaddpojqpqpkwbpekg.exe
- %WINDIR%\gddgapmr\abdsmd
- '34.##9.100.209':443
- DNS ASK he###single.net
- DNS ASK di####ultcharge.net
- DNS ASK he###charge.net
- DNS ASK di#####ltdifference.net
- DNS ASK he####ifference.net
- DNS ASK di####ultevery.net
- 'C:\gddgapmr\qcmaddpojqpqpkwbpekg.exe'
- 'C:\gddgapmr\tjumzslvg.exe'
- 'C:\gddgapmr\lcscebyvaqw.exe' "c:\gddgapmr\tjumzslvg.exe"