Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\Service Access Controls SPP Application] 'Start' = '00000002'
- 'C:\cjelhoxx\vlltkiyzteuj.exe' "c:\cjelhoxx\jlpbmlxdkaqu.exe"
- 'C:\cjelhoxx\jlpbmlxdkaqu.exe'
- 'C:\cjelhoxx\uvsx8c01x0j5ovhj.exe'
- C:\cjelhoxx\jlpbmlxdkaqu.exe
- C:\cjelhoxx\vlltkiyzteuj.exe
- C:\cjelhoxx\iaxf3boi
- %WINDIR%\cjelhoxx\hsytqheda
- C:\cjelhoxx\hsytqheda
- C:\cjelhoxx\uvsx8c01x0j5ovhj.exe
- C:\cjelhoxx\vlltkiyzteuj.exe
- C:\cjelhoxx\jlpbmlxdkaqu.exe
- C:\cjelhoxx\uvsx8c01x0j5ovhj.exe
- %WINDIR%\cjelhoxx\hsytqheda
- DNS ASK th###health.net
- DNS ASK pr####tseparate.net
- DNS ASK pr####thealth.net
- DNS ASK pr####tclothes.net
- DNS ASK th####lothes.net
- DNS ASK dn#.##ftncsi.com
- DNS ASK cl###safety.net
- DNS ASK th###future.net
- DNS ASK th####eparate.net
- DNS ASK cl###future.net
- ClassName: 'Shell_TrayWnd' WindowName: ''