Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\Tablet Manager Web Audio] 'Start' = '00000002'
- 'C:\zgkaepqs\nbtyttpdrmaf.exe' "c:\zgkaepqs\fpotwmrscvvi.exe"
- 'C:\zgkaepqs\fpotwmrscvvi.exe'
- 'C:\zgkaepqs\xx9gjipulhbc7a7wu.exe'
- C:\zgkaepqs\fpotwmrscvvi.exe
- C:\zgkaepqs\nbtyttpdrmaf.exe
- C:\zgkaepqs\rg5tzg
- %WINDIR%\zgkaepqs\gjgp4f
- C:\zgkaepqs\gjgp4f
- C:\zgkaepqs\xx9gjipulhbc7a7wu.exe
- C:\zgkaepqs\nbtyttpdrmaf.exe
- C:\zgkaepqs\fpotwmrscvvi.exe
- C:\zgkaepqs\xx9gjipulhbc7a7wu.exe
- %WINDIR%\zgkaepqs\gjgp4f
- DNS ASK di####ultforest.net
- DNS ASK he###always.net
- DNS ASK he###forest.net
- DNS ASK ne####arywheat.net
- DNS ASK pl####ntwheat.net
- DNS ASK dn#.##ftncsi.com
- DNS ASK he###wheat.net
- DNS ASK di####ultanger.net
- DNS ASK di####ultalways.net
- DNS ASK he###anger.net
- ClassName: 'Shell_TrayWnd' WindowName: ''