Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\Human Performance Support Proxy] 'Start' = '00000002'
- 'C:\zwkuygkew\etvqgjsojli.exe' "c:\zwkuygkew\pfpjuztbhodo.exe"
- 'C:\zwkuygkew\pfpjuztbhodo.exe'
- 'C:\zwkuygkew\lnzqs8cavc1eiacbzry.exe'
- '<SYSTEM32>\wermgr.exe' "-queuereporting_svc" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_pfpjuztbhodo.exe_b0934e5b0708945ce88b2d67b83b56285f84f85_cab_1b063986"
- C:\zwkuygkew\pfpjuztbhodo.exe
- C:\zwkuygkew\etvqgjsojli.exe
- C:\zwkuygkew\gcss7auiuhqu
- %WINDIR%\zwkuygkew\qgfgm8mtnzhu
- C:\zwkuygkew\qgfgm8mtnzhu
- C:\zwkuygkew\lnzqs8cavc1eiacbzry.exe
- C:\zwkuygkew\etvqgjsojli.exe
- C:\zwkuygkew\pfpjuztbhodo.exe
- C:\zwkuygkew\lnzqs8cavc1eiacbzry.exe
- %WINDIR%\zwkuygkew\qgfgm8mtnzhu
- C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_pfpjuztbhodo.exe_b0934e5b0708945ce88b2d67b83b56285f84f85_cab_1b063986\Report.wer.tmp в C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_pfpjuztbhodo.exe_b0934e5b0708945ce88b2d67b83b56285f84f85_cab_1b063986\Report.wer
- DNS ASK th###forest.net
- DNS ASK ch###forest.net
- DNS ASK su###rwheat.net
- DNS ASK wi###nwheat.net
- DNS ASK dn#.##ftncsi.com
- DNS ASK th###anger.net
- DNS ASK th###always.net
- DNS ASK ch###always.net
- ClassName: 'Shell_TrayWnd' WindowName: ''