Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\COM Files Certificate Brightness Modules] 'Start' = '00000002'
- 'C:\ourxwlxbpzkdq\nelrmmrvzfjh.exe' "c:\ourxwlxbpzkdq\inrpvao.exe"
- 'C:\ourxwlxbpzkdq\inrpvao.exe'
- 'C:\ourxwlxbpzkdq\gq0t8u2wpiyarwrhlc0e.exe'
- '<SYSTEM32>\wermgr.exe' "-queuereporting_svc" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_inrpvao.exe_9f6d7fc83432b6b78224d89762e2369bd963859_cab_18b2a218"
- C:\ourxwlxbpzkdq\inrpvao.exe
- C:\ourxwlxbpzkdq\nelrmmrvzfjh.exe
- C:\ourxwlxbpzkdq\qpmy3zwnubb
- %WINDIR%\ourxwlxbpzkdq\cgxjvsqxfvc
- C:\ourxwlxbpzkdq\cgxjvsqxfvc
- C:\ourxwlxbpzkdq\gq0t8u2wpiyarwrhlc0e.exe
- C:\ourxwlxbpzkdq\nelrmmrvzfjh.exe
- C:\ourxwlxbpzkdq\inrpvao.exe
- C:\ourxwlxbpzkdq\gq0t8u2wpiyarwrhlc0e.exe
- %WINDIR%\ourxwlxbpzkdq\cgxjvsqxfvc
- C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_inrpvao.exe_9f6d7fc83432b6b78224d89762e2369bd963859_cab_18b2a218\Report.wer.tmp в C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_inrpvao.exe_9f6d7fc83432b6b78224d89762e2369bd963859_cab_18b2a218\Report.wer
- DNS ASK re####erapple.net
- DNS ASK wo###apple.net
- DNS ASK re####erbuilt.net
- DNS ASK wo###built.net
- DNS ASK re####erfather.net
- DNS ASK dn#.##ftncsi.com
- DNS ASK fo###tcarry.net
- DNS ASK wo###father.net
- DNS ASK in####secarry.net
- ClassName: 'Shell_TrayWnd' WindowName: ''