Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\Spooler Driver Group Time Procedure] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\Spooler Driver Group Time Procedure] 'ImagePath' = 'C:\cfgtngbaianlwl\yfqwmgytw.exe'
- 'Spooler Driver Group Time Procedure' C:\cfgtngbaianlwl\yfqwmgytw.exe
- %WINDIR%\cfgtngbaianlwl\thosgktsydyt
- C:\cfgtngbaianlwl\thosgktsydyt
- C:\cfgtngbaianlwl\fdtek31isnnosnkq32ryd.exe
- C:\cfgtngbaianlwl\yfqwmgytw.exe
- C:\cfgtngbaianlwl\wvijfdzi.exe
- C:\cfgtngbaianlwl\yfqwmgytw.exe
- C:\cfgtngbaianlwl\wvijfdzi.exe
- %WINDIR%\cfgtngbaianlwl\thosgktsydyt
- C:\cfgtngbaianlwl\fdtek31isnnosnkq32ryd.exe
- %WINDIR%\cfgtngbaianlwl\thosgktsydyt
- DNS ASK hu####dletter.net
- DNS ASK jo#####different.net
- DNS ASK hu#####different.net
- 'C:\cfgtngbaianlwl\fdtek31isnnosnkq32ryd.exe'
- 'C:\cfgtngbaianlwl\yfqwmgytw.exe'
- 'C:\cfgtngbaianlwl\wvijfdzi.exe' "c:\cfgtngbaianlwl\yfqwmgytw.exe"