Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Foundation Scheduler Connect Bluetooth' = 'C:\itfwttugst\iznpfacbrkw.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Bluetooth Provider DLL Firewall Shell] 'Start' = '00000002'
- 'C:\itfwttugst\oerbhumpz.exe' "c:\itfwttugst\iznpfacbrkw.exe"
- 'C:\itfwttugst\iznpfacbrkw.exe'
- 'C:\itfwttugst\dhyc4su8y7lmftwyh5.exe'
- C:\itfwttugst\iznpfacbrkw.exe
- C:\itfwttugst\oerbhumpz.exe
- C:\itfwttugst\dhyc4su8y7lmftwyh5.exe
- %WINDIR%\itfwttugst\vzhvjzuxru
- C:\itfwttugst\vzhvjzuxru
- C:\itfwttugst\oerbhumpz.exe
- C:\itfwttugst\iznpfacbrkw.exe
- C:\itfwttugst\dhyc4su8y7lmftwyh5.exe
- %WINDIR%\itfwttugst\vzhvjzuxru
- 'ci####ttesister.net':80
- 'pi####esister.net':80
- http://ci####ttesister.net/index.php
- http://pi####esister.net/index.php
- DNS ASK ci####ttelabor.net
- DNS ASK pi####elabor.net
- DNS ASK fa####silver.net
- DNS ASK ch####ensilver.net
- DNS ASK ci####ttesister.net
- DNS ASK pi####esister.net
- DNS ASK ci####ttevalley.net
- DNS ASK pi####evalley.net
- ClassName: 'Shell_TrayWnd' WindowName: ''