Техническая информация
- [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] 'AppInit_DLLs' = ' '
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows] 'LoadAppInit_DLLs' = '00000001'
- [HKLM\System\CurrentControlSet\Services\6ad8e7a1] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\6ad8e7a1] 'ImagePath' = '"<SYSTEM32>\rundll32.exe" "%ProgramFiles(x86)%\PragmaMonitor\PragmaMonitor.dll",serv'
- '6ad8e7a1' <SYSTEM32> undll32.exe" "%ProgramFiles(x86)%\PragmaMonitor\PragmaMonitor.dll",ser
- %TEMP%\tf00294823.dll
- %ProgramFiles(x86)%\pragmamonitor\pragmamonitor.dll
- %TEMP%\tf00294823.dll
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- 'bb#.com':80
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- DNS ASK bb#.com
- DNS ASK te###ne.info
- DNS ASK te##ine.net
- DNS ASK fa###rygood.net
- '%WINDIR%\syswow64\rundll32.exe' "%ProgramFiles(x86)%\PragmaMonitor\PragmaMonitor.dll",serv -install
- '<SYSTEM32>\rundll32.exe' "%ProgramFiles(x86)%\PragmaMonitor\PragmaMonitor.dll",serv