Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Engine Web Server Netlogon' = '%APPDATA%\Roaming\liyjlqbglefoide\svudzdexqwh.exe'
- '%APPDATA%\Roaming\liyjlqbglefoide\gztyxeekypws.exe' "%APPDATA%\Roaming\liyjlqbglefoide\svudzdexqwh.exe"
- '%APPDATA%\Roaming\liyjlqbglefoide\svudzdexqwh.exe'
- %APPDATA%\Roaming\liyjlqbglefoide\svudzdexqwh.ixzss
- %APPDATA%\Roaming\liyjlqbglefoide\gztyxeekypws.exe
- %APPDATA%\Roaming\liyjlqbglefoide\svudzdexqwh.exe
- %APPDATA%\Roaming\liyjlqbglefoide\gztyxeekypws.exe
- %APPDATA%\Roaming\liyjlqbglefoide\svudzdexqwh.exe
- DNS ASK fi####minute.net
- DNS ASK th####flower.net
- DNS ASK th####minute.net
- DNS ASK th####special.net
- DNS ASK fi####special.net
- DNS ASK fi####flower.net
- DNS ASK ri####pecial.net
- DNS ASK wh####rspecial.net
- DNS ASK dn#.##ftncsi.com
- DNS ASK ri###corner.net
- DNS ASK wh####rcorner.net
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''