Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\Backup Auto Name Location Application File] 'Start' = '00000002'
- 'C:\zbjdfikavd\gglxigwanhz.exe' "c:\zbjdfikavd\gvnsvmchtqpc.exe"
- 'C:\zbjdfikavd\gvnsvmchtqpc.exe'
- 'C:\zbjdfikavd\vx1t7zv8skvtxm3wp2p3n.exe'
- C:\zbjdfikavd\gvnsvmchtqpc.exe
- C:\zbjdfikavd\gglxigwanhz.exe
- C:\zbjdfikavd\tdugu5ccl
- %WINDIR%\zbjdfikavd\kbf8wxbpdei
- C:\zbjdfikavd\kbf8wxbpdei
- C:\zbjdfikavd\vx1t7zv8skvtxm3wp2p3n.exe
- C:\zbjdfikavd\gglxigwanhz.exe
- C:\zbjdfikavd\gvnsvmchtqpc.exe
- C:\zbjdfikavd\vx1t7zv8skvtxm3wp2p3n.exe
- %WINDIR%\zbjdfikavd\kbf8wxbpdei
- DNS ASK va####sshort.net
- DNS ASK re####should.net
- DNS ASK re###nshort.net
- DNS ASK re####opinion.net
- DNS ASK va####sopinion.net
- DNS ASK va####sshould.net
- DNS ASK ge####opinion.net
- DNS ASK he####pinion.net
- DNS ASK dn#.##ftncsi.com
- DNS ASK ge####promise.net
- DNS ASK he####romise.net
- ClassName: 'Shell_TrayWnd' WindowName: ''