Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Key TP Machine Reporting Auto RPC Intelligent' = 'C:\llrkjajsvmjmr\lrshouaklshy.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Support Mapper Port Auto Link-Layer Modules] 'ImagePath' = 'C:\llrkjajsvmjmr\lrshouaklshy.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Support Mapper Port Auto Link-Layer Modules] 'Start' = '00000002'
- 'C:\llrkjajsvmjmr\frrtutyijexr.exe' "c:\llrkjajsvmjmr\lrshouaklshy.exe"
- 'C:\llrkjajsvmjmr\lrshouaklshy.exe'
- 'C:\llrkjajsvmjmr\gdb4s2ru6fhan8kuceoaow.exe'
- C:\llrkjajsvmjmr\lrshouaklshy.exe
- C:\llrkjajsvmjmr\frrtutyijexr.exe
- C:\llrkjajsvmjmr\uamh1vh1l0tb
- %WINDIR%\llrkjajsvmjmr\lcpbvfbuec1
- C:\llrkjajsvmjmr\lcpbvfbuec1
- C:\llrkjajsvmjmr\gdb4s2ru6fhan8kuceoaow.exe
- C:\llrkjajsvmjmr\frrtutyijexr.exe
- C:\llrkjajsvmjmr\lrshouaklshy.exe
- C:\llrkjajsvmjmr\gdb4s2ru6fhan8kuceoaow.exe
- %WINDIR%\llrkjajsvmjmr\lcpbvfbuec1
- %WINDIR%\llrkjajsvmjmr\lcpbvfbuec1
- '19#.#7.134.20':44965
- '22#.#1.110.45':48008
- '81.##4.87.112':37714
- '18#.#39.139.100':37599
- '20#.#7.225.58':33073
- '79.##3.139.198':21201
- '21#.#7.168.28':52231
- '88.#48.36.4':25752
- '19#.#6.240.249':21875
- '10#.#46.77.146':33927
- '17#.#50.138.208':20422
- '41.##8.41.238':29356
- ClassName: 'Shell_TrayWnd' WindowName: ''