Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\Encrypting WWAN Smart Wired Font] 'Start' = '00000002'
- 'C:\zoqqhgqmhyiixe\jrknmoikcpd.exe' "c:\zoqqhgqmhyiixe\wazweljw.exe"
- 'C:\zoqqhgqmhyiixe\wazweljw.exe'
- 'C:\zoqqhgqmhyiixe\yslh8c7ulfzwsmjqcco.exe'
- C:\zoqqhgqmhyiixe\wazweljw.exe
- C:\zoqqhgqmhyiixe\jrknmoikcpd.exe
- C:\zoqqhgqmhyiixe\sqlxz8
- %WINDIR%\zoqqhgqmhyiixe\mudbazpq2
- C:\zoqqhgqmhyiixe\mudbazpq2
- C:\zoqqhgqmhyiixe\yslh8c7ulfzwsmjqcco.exe
- C:\zoqqhgqmhyiixe\jrknmoikcpd.exe
- C:\zoqqhgqmhyiixe\wazweljw.exe
- C:\zoqqhgqmhyiixe\yslh8c7ulfzwsmjqcco.exe
- %WINDIR%\zoqqhgqmhyiixe\mudbazpq2
- DNS ASK am####arrive.net
- DNS ASK we####roffice.net
- DNS ASK we####rarrive.net
- DNS ASK cl###supply.net
- DNS ASK th###supply.net
- DNS ASK am####office.net
- DNS ASK we####rsupply.net
- DNS ASK am####supply.net
- DNS ASK dn#.##ftncsi.com
- DNS ASK we####rdistance.net
- DNS ASK am####distance.net
- ClassName: 'Shell_TrayWnd' WindowName: ''