Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\Play Agent Trap Layer AutoConfig] 'Start' = '00000002'
- 'C:\lqgcquwtz\tvzzmvjhs.exe' "c:\lqgcquwtz\afuacmgoii.exe"
- 'C:\lqgcquwtz\afuacmgoii.exe'
- 'C:\lqgcquwtz\pnat8bm6agysasaqeia.exe'
- '<SYSTEM32>\wermgr.exe' "-queuereporting_svc" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_afuacmgoii.exe_35dc4d90cbe030161023c14ac3ed5ddd518b8a81_cab_148643f2"
- '<SYSTEM32>\taskhost.exe' -k WerSvcGroup
- C:\lqgcquwtz\afuacmgoii.exe
- C:\lqgcquwtz\tvzzmvjhs.exe
- C:\lqgcquwtz\brwsteybu1
- %WINDIR%\lqgcquwtz\peqbgkyin
- C:\lqgcquwtz\peqbgkyin
- C:\lqgcquwtz\pnat8bm6agysasaqeia.exe
- C:\lqgcquwtz\tvzzmvjhs.exe
- C:\lqgcquwtz\afuacmgoii.exe
- C:\lqgcquwtz\pnat8bm6agysasaqeia.exe
- %WINDIR%\lqgcquwtz\peqbgkyin
- C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_afuacmgoii.exe_35dc4d90cbe030161023c14ac3ed5ddd518b8a81_cab_148643f2\Report.wer.tmp в C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_afuacmgoii.exe_35dc4d90cbe030161023c14ac3ed5ddd518b8a81_cab_148643f2\Report.wer
- DNS ASK ra####caught.net
- DNS ASK mo#####president.net
- DNS ASK st####estrong.net
- DNS ASK mo####gcaught.net
- DNS ASK ra####president.net
- DNS ASK ra####trouble.net
- DNS ASK mo####gstrong.net
- DNS ASK mo####gtrouble.net
- DNS ASK dn#.##ftncsi.com
- ClassName: 'Shell_TrayWnd' WindowName: ''