Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\Process Group Remote iSCSI Client Awareness] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\Process Group Remote iSCSI Client Awareness] 'ImagePath' = 'C:\wwwcwxyr\hjebnzempsi.exe'
- 'Process Group Remote iSCSI Client Awareness' C:\wwwcwxyr\hjebnzempsi.exe
- %WINDIR%\wwwcwxyr\dfvknkuirh
- C:\wwwcwxyr\dfvknkuirh
- C:\wwwcwxyr\ldj48hxkdm1zzlupqwe.exe
- C:\wwwcwxyr\hjebnzempsi.exe
- C:\wwwcwxyr\dkrbrrigtf.exe
- C:\wwwcwxyr\fhitwz8
- C:\wwwcwxyr\hjebnzempsi.exe
- C:\wwwcwxyr\dkrbrrigtf.exe
- %WINDIR%\wwwcwxyr\dfvknkuirh
- C:\wwwcwxyr\ldj48hxkdm1zzlupqwe.exe
- %WINDIR%\wwwcwxyr\dfvknkuirh
- DNS ASK ci#####tegeneral.net
- DNS ASK pi####einclude.net
- DNS ASK ci#####teinclude.net
- 'C:\wwwcwxyr\ldj48hxkdm1zzlupqwe.exe'
- 'C:\wwwcwxyr\hjebnzempsi.exe'
- 'C:\wwwcwxyr\dkrbrrigtf.exe' "c:\wwwcwxyr\hjebnzempsi.exe"