Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Klfcwc jgmauw] 'Start' = '00000002'
- %PROGRAM_FILES%\Windows Qgtaqa\Qgsslog.exe
- C:\Yrpzsk.exe
- <SYSTEM32>\wscript.exe "C:\4908.vbs"
- <SYSTEM32>\wscript.exe "C:\8517.vbs"
- %PROGRAM_FILES%\Windows Qgtaqa\Qgsslog.exe
- C:\4908.vbs
- C:\Yrpzsk.exe
- C:\8517.vbs
- C:\4908.vbs
- C:\Yrpzsk.exe
- C:\8517.vbs
- 'www.ba##es.com':2102
- DNS ASK www.ba##es.com