Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Multimedia Certificate Telephony' = 'C:\jbvlrmrmgckrz\ukxlxjazdgju.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Shell BitLocker Counter Tracking User] 'ImagePath' = 'C:\jbvlrmrmgckrz\ukxlxjazdgju.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Shell BitLocker Counter Tracking User] 'Start' = '00000002'
- 'C:\jbvlrmrmgckrz\cvaqlimfv.exe' "c:\jbvlrmrmgckrz\ukxlxjazdgju.exe"
- 'C:\jbvlrmrmgckrz\ukxlxjazdgju.exe'
- 'C:\jbvlrmrmgckrz\zyi3epyhsrmji1bnf.exe'
- C:\jbvlrmrmgckrz\ukxlxjazdgju.exe
- C:\jbvlrmrmgckrz\cvaqlimfv.exe
- C:\jbvlrmrmgckrz\aqnqaqr1o
- %WINDIR%\jbvlrmrmgckrz\tcyjvrjh
- C:\jbvlrmrmgckrz\tcyjvrjh
- C:\jbvlrmrmgckrz\zyi3epyhsrmji1bnf.exe
- C:\jbvlrmrmgckrz\cvaqlimfv.exe
- C:\jbvlrmrmgckrz\ukxlxjazdgju.exe
- C:\jbvlrmrmgckrz\zyi3epyhsrmji1bnf.exe
- %WINDIR%\jbvlrmrmgckrz\tcyjvrjh
- %WINDIR%\jbvlrmrmgckrz\tcyjvrjh
- 'ch####enreceive.net':80
- 'fa####receive.net':80
- 'ch####enbranch.net':80
- 'fa####believe.net':80
- http://ch####enreceive.net/index.php
- http://fa####receive.net/index.php
- http://ch####enbranch.net/index.php
- http://fa####believe.net/index.php
- DNS ASK ch####enreceive.net
- DNS ASK fa####receive.net
- DNS ASK ch####enquarter.net
- DNS ASK fa####believe.net
- DNS ASK ch####enbranch.net
- DNS ASK fa####branch.net
- DNS ASK ch####enbelieve.net
- ClassName: 'Shell_TrayWnd' WindowName: ''