Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Cache Biometric Computer Helper SPP' = 'C:\bvewahgbukia\giqgkutnn.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Mapper Netlogon Level PNRP Manager DCOM Reporting] 'Start' = '00000002'
- 'C:\bvewahgbukia\ttvhdkewho.exe' "c:\bvewahgbukia\giqgkutnn.exe"
- 'C:\bvewahgbukia\giqgkutnn.exe'
- 'C:\bvewahgbukia\fvlq58i0vufsjnprv5.exe'
- C:\bvewahgbukia\giqgkutnn.exe
- C:\bvewahgbukia\ttvhdkewho.exe
- C:\bvewahgbukia\fvlq58i0vufsjnprv5.exe
- %WINDIR%\bvewahgbukia\bngj7tlycq9d
- C:\bvewahgbukia\bngj7tlycq9d
- C:\bvewahgbukia\ttvhdkewho.exe
- C:\bvewahgbukia\giqgkutnn.exe
- C:\bvewahgbukia\fvlq58i0vufsjnprv5.exe
- %WINDIR%\bvewahgbukia\bngj7tlycq9d
- 'be####earound.net':80
- http://be####earound.net/index.php
- DNS ASK ex####complete.net
- DNS ASK be####ecomplete.net
- DNS ASK pe####welcome.net
- DNS ASK be####earound.net
- DNS ASK ex###tproud.net
- DNS ASK be####eproud.net
- ClassName: 'Shell_TrayWnd' WindowName: ''