Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Experience Intelligent Event Alerts Process Now' = '%APPDATA%\Roaming\bxezmvum\yaxednjouxqp.exe'
- '%APPDATA%\Roaming\bxezmvum\wviwgueoe.exe' "%APPDATA%\Roaming\bxezmvum\yaxednjouxqp.exe"
- '%APPDATA%\Roaming\bxezmvum\yaxednjouxqp.exe'
- %APPDATA%\Roaming\bxezmvum\yaxednjouxqp.kfd
- %APPDATA%\Roaming\bxezmvum\wviwgueoe.exe
- %APPDATA%\Roaming\bxezmvum\yaxednjouxqp.exe
- %APPDATA%\Roaming\bxezmvum\yaxednjouxqp.exe
- DNS ASK do###eclean.net
- DNS ASK fe###wclean.net
- DNS ASK fe###wpaint.net
- DNS ASK fe####course.net
- DNS ASK do###epaint.net
- DNS ASK pr####course.net
- DNS ASK do####course.net
- DNS ASK dn#.##ftncsi.com
- DNS ASK pr###ywomen.net
- DNS ASK do###rwomen.net
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''