Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WinHTTP RPC Defragmenter' = '%APPDATA%\egtyvktwix\ffzat1rt.exe'
- '%APPDATA%\egtyvktwix\aalkvhk8r3.exe' "%APPDATA%\egtyvktwix\ffzat1rt.exe"
- '%APPDATA%\egtyvktwix\ffzat1rt.exe'
- %APPDATA%\egtyvktwix\ffzat1rt.nnp
- %APPDATA%\egtyvktwix\aalkvhk8r3.exe
- %APPDATA%\egtyvktwix\ffzat1rt.exe
- %APPDATA%\egtyvktwix\ffzat1rt.exe
- 'wa###divide.net':80
- 'wa###bottle.net':80
- wa###divide.net/index.php?em#################################################
- wa###bottle.net/index.php?em#################################################
- DNS ASK sm###bottle.net
- DNS ASK wo###bottle.net
- DNS ASK sm####othing.net
- DNS ASK pa###stream.net
- DNS ASK sm###divide.net
- DNS ASK wo###divide.net
- DNS ASK wa###divide.net
- DNS ASK th####tdivide.net
- DNS ASK wa###bottle.net
- DNS ASK wo####othing.net
- DNS ASK sm###stream.net
- DNS ASK wo###stream.net
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'Indicator' WindowName: '(null)'