Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'iSCSI Agent PNRP Peer Function KtmRm Auto Office' = 'C:\khhppkk\airdcsbwi.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Awareness Adapter Software Windows] 'Start' = '00000002'
- 'C:\khhppkk\bxxjbeyojs.exe' "c:\khhppkk\airdcsbwi.exe"
- 'C:\khhppkk\airdcsbwi.exe'
- 'C:\khhppkk\ow35cqcaqhdcug5h3o.exe'
- C:\khhppkk\airdcsbwi.exe
- C:\khhppkk\bxxjbeyojs.exe
- C:\khhppkk\ow35cqcaqhdcug5h3o.exe
- %WINDIR%\khhppkk\gwkmat6k
- C:\khhppkk\gwkmat6k
- C:\khhppkk\bxxjbeyojs.exe
- C:\khhppkk\airdcsbwi.exe
- C:\khhppkk\ow35cqcaqhdcug5h3o.exe
- %WINDIR%\khhppkk\gwkmat6k
- 'st###nature.net':80
- 'st####thneedle.net':80
- 'st###needle.net':80
- 'st####thnature.net':80
- 'pr####eneedle.net':80
- 'de####needle.net':80
- 'de####govern.net':80
- http://st###nature.net/index.php
- http://st####thneedle.net/index.php
- http://st###needle.net/index.php
- http://st####thnature.net/index.php
- http://pr####eneedle.net/index.php
- http://de####needle.net/index.php
- http://de####govern.net/index.php
- DNS ASK st###nature.net
- DNS ASK st####thnature.net
- DNS ASK st####thneedle.net
- DNS ASK st####thenough.net
- DNS ASK st###needle.net
- DNS ASK de####govern.net
- DNS ASK de####needle.net
- DNS ASK pr####eneedle.net
- DNS ASK pr####eenough.net
- DNS ASK pr####egovern.net
- DNS ASK de####enough.net
- ClassName: 'Shell_TrayWnd' WindowName: ''