Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Offline Tools Adapter Problem Presentation' = 'C:\pqtxkevancbnnr\nkhtprimg.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Event TP TPM Software Disk Proxy] 'ImagePath' = 'C:\pqtxkevancbnnr\nkhtprimg.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Event TP TPM Software Disk Proxy] 'Start' = '00000002'
- 'C:\pqtxkevancbnnr\ohgmugqziahv.exe' "c:\pqtxkevancbnnr\nkhtprimg.exe"
- 'C:\pqtxkevancbnnr\nkhtprimg.exe'
- 'C:\pqtxkevancbnnr\zco31uvlniuy8uvy6.exe'
- C:\pqtxkevancbnnr\nkhtprimg.exe
- C:\pqtxkevancbnnr\ohgmugqziahv.exe
- C:\pqtxkevancbnnr\yokpnv
- %WINDIR%\pqtxkevancbnnr\ninanfmcdy
- C:\pqtxkevancbnnr\ninanfmcdy
- C:\pqtxkevancbnnr\zco31uvlniuy8uvy6.exe
- C:\pqtxkevancbnnr\ohgmugqziahv.exe
- C:\pqtxkevancbnnr\nkhtprimg.exe
- C:\pqtxkevancbnnr\zco31uvlniuy8uvy6.exe
- %WINDIR%\pqtxkevancbnnr\ninanfmcdy
- %WINDIR%\pqtxkevancbnnr\ninanfmcdy
- '18#.#42.73.242':26662
- '41.#6.20.41':48405
- '17#.#50.138.208':20422
- '41.##8.41.238':29356
- '78.##5.171.93':23699
- '86.##.69.232':41590
- '18#.#39.143.239':37599
- '17#.37.2.43':44303
- ClassName: 'Shell_TrayWnd' WindowName: ''