Техническая информация
- [HKLM\System\CurrentControlSet\Services\System Netlogon Layer SNMP Portable] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\System Netlogon Layer SNMP Portable] 'ImagePath' = 'C:\zotlofqk\efclvwh.exe'
- 'System Netlogon Layer SNMP Portable' C:\zotlofqk\efclvwh.exe
- %WINDIR%\zotlofqk\naymeczp
- C:\zotlofqk\naymeczp
- C:\zotlofqk\q8jn4bpbwnv2drd48b.exe
- C:\zotlofqk\efclvwh.exe
- C:\zotlofqk\afqxlakhs.exe
- C:\zotlofqk\q6rkonat
- C:\zotlofqk\efclvwh.exe
- C:\zotlofqk\afqxlakhs.exe
- %WINDIR%\zotlofqk\naymeczp
- C:\zotlofqk\q8jn4bpbwnv2drd48b.exe
- %WINDIR%\zotlofqk\naymeczp
- DNS ASK de####period.net
- DNS ASK fo####dperiod.net
- DNS ASK de####however.net
- DNS ASK fo####dhowever.net
- DNS ASK an####choose.net
- DNS ASK gl###choose.net
- DNS ASK an####although.net
- DNS ASK gl####lthough.net
- 'C:\zotlofqk\q8jn4bpbwnv2drd48b.exe'
- 'C:\zotlofqk\efclvwh.exe'
- 'C:\zotlofqk\afqxlakhs.exe' "c:\zotlofqk\efclvwh.exe"