Техническая информация
- [HKLM\System\CurrentControlSet\Services\Mnoghi Abctu] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Mnoghi Abctu] 'ImagePath' = '<SYSTEM32>\Sklde.exe -auto'
- 'Mnoghi Abctu' <SYSTEM32>\Sklde.exe -auto
- %APPDATA%\microsoft\windows\sendto\intel h graphies drivers for seerch rrotocol lost.exe
- %WINDIR%\syswow64\sklde.exe
- %APPDATA%\microsoft\windows\sendto\intel h graphies drivers for seerch rrotocol lost.exe
- %WINDIR%\syswow64\sklde.exe
- DNS ASK s0.#100.vip
- '%APPDATA%\microsoft\windows\sendto\intel h graphies drivers for seerch rrotocol lost.exe'
- '%WINDIR%\syswow64\sklde.exe' -auto
- '%WINDIR%\syswow64\sklde.exe' -acsi