Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\CNG Framework Auto-Discovery Window] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\CNG Framework Auto-Discovery Window] 'ImagePath' = 'C:\hffpijyojecd\ojscukqomopd.exe'
- 'CNG Framework Auto-Discovery Window' C:\hffpijyojecd\ojscukqomopd.exe
- %WINDIR%\hffpijyojecd\ovc6so
- C:\hffpijyojecd\ovc6so
- C:\hffpijyojecd\amn7jtrqisl0qnkrxpbnr.exe
- C:\hffpijyojecd\ojscukqomopd.exe
- C:\hffpijyojecd\oqczxwxn.exe
- C:\hffpijyojecd\ojscukqomopd.exe
- C:\hffpijyojecd\oqczxwxn.exe
- %WINDIR%\hffpijyojecd\ovc6so
- C:\hffpijyojecd\amn7jtrqisl0qnkrxpbnr.exe
- %WINDIR%\hffpijyojecd\ovc6so
- DNS ASK ci#####tegeneral.net
- DNS ASK pi####einclude.net
- DNS ASK ci#####teinclude.net
- DNS ASK pi####enorth.net
- 'C:\hffpijyojecd\amn7jtrqisl0qnkrxpbnr.exe'
- 'C:\hffpijyojecd\ojscukqomopd.exe'
- 'C:\hffpijyojecd\oqczxwxn.exe' "c:\hffpijyojecd\ojscukqomopd.exe"