Техническая информация
- [HKLM\System\CurrentControlSet\Services\Protection Desktop Fax AuthIP User Helper] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Protection Desktop Fax AuthIP User Helper] 'ImagePath' = 'C:\zczfcudv\pmtbkkt.exe'
- 'Protection Desktop Fax AuthIP User Helper' C:\zczfcudv\pmtbkkt.exe
- %WINDIR%\zczfcudv\hthz6a
- C:\zczfcudv\hthz6a
- C:\zczfcudv\xcgtroj1fidtpukwq3.exe
- C:\zczfcudv\pmtbkkt.exe
- C:\zczfcudv\hfnrfalmqyv.exe
- C:\zczfcudv\m3udizap
- C:\zczfcudv\pmtbkkt.exe
- C:\zczfcudv\hfnrfalmqyv.exe
- %WINDIR%\zczfcudv\hthz6a
- C:\zczfcudv\xcgtroj1fidtpukwq3.exe
- %WINDIR%\zczfcudv\hthz6a
- DNS ASK de####training.net
- DNS ASK fo####dtraining.net
- DNS ASK de###estorm.net
- DNS ASK fo####dstorm.net
- DNS ASK de####thrown.net
- DNS ASK fo####dthrown.net
- DNS ASK an####hunger.net
- DNS ASK gl###hunger.net
- 'C:\zczfcudv\xcgtroj1fidtpukwq3.exe'
- 'C:\zczfcudv\pmtbkkt.exe'
- 'C:\zczfcudv\hfnrfalmqyv.exe' "c:\zczfcudv\pmtbkkt.exe"