Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\Reporting Protocol WinHTTP Bus Network] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\Reporting Protocol WinHTTP Bus Network] 'ImagePath' = 'C:\jdpjqqpspmft\dlxsbmqk.exe'
- 'Reporting Protocol WinHTTP Bus Network' C:\jdpjqqpspmft\dlxsbmqk.exe
- %WINDIR%\jdpjqqpspmft\aqaft27cs
- C:\jdpjqqpspmft\aqaft27cs
- C:\jdpjqqpspmft\zujjd4svmjpbulppdc.exe
- C:\jdpjqqpspmft\dlxsbmqk.exe
- C:\jdpjqqpspmft\igreijltdvp.exe
- C:\jdpjqqpspmft\z8zdocyll
- C:\jdpjqqpspmft\dlxsbmqk.exe
- C:\jdpjqqpspmft\igreijltdvp.exe
- %WINDIR%\jdpjqqpspmft\aqaft27cs
- C:\jdpjqqpspmft\zujjd4svmjpbulppdc.exe
- %WINDIR%\jdpjqqpspmft\aqaft27cs
- DNS ASK ev####gtrouble.net
- DNS ASK bu#####gpresident.net
- DNS ASK ev#####president.net
- 'C:\jdpjqqpspmft\zujjd4svmjpbulppdc.exe'
- 'C:\jdpjqqpspmft\dlxsbmqk.exe'
- 'C:\jdpjqqpspmft\igreijltdvp.exe' "c:\jdpjqqpspmft\dlxsbmqk.exe"