Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\ge] 'Start' = '00000002'
- '%WINDIR%\QUlxDtfKXiHFyPI.exe'
- '<Текущая директория>\rcubipve.exe'
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\config\systemprofile\AppData\Local\bq5uzce1f3.dll
- %WINDIR%\QUlxDtfKXiHFyPI.exe
- <Текущая директория>\rcubipve.exe
- <Текущая директория>\rcubipve.exe
- '18#.#20.194.101':13083
- DNS ASK st##.#oipstunt.com
- DNS ASK st##.##ktortel.com.au
- DNS ASK st###.l.google.com
- DNS ASK st##.ipshka.com
- DNS ASK st##.#.google.com
- DNS ASK dn#.##ftncsi.com
- DNS ASK google.com
- DNS ASK microsoft.com
- DNS ASK st##.###vices.mozilla.com
- DNS ASK st##.#oip.aebc.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '#32770' WindowName: ''