Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Internet Source Base Device' = 'C:\jbihzecbhribeo\lmtnzkavp.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Offline Copy AutoConnect Tools] 'ImagePath' = 'C:\jbihzecbhribeo\lmtnzkavp.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Offline Copy AutoConnect Tools] 'Start' = '00000002'
- 'C:\jbihzecbhribeo\ewrihtalizme.exe' "c:\jbihzecbhribeo\lmtnzkavp.exe"
- 'C:\jbihzecbhribeo\lmtnzkavp.exe'
- 'C:\jbihzecbhribeo\mpm2qcswhojeyp3.exe'
- C:\jbihzecbhribeo\lmtnzkavp.exe
- C:\jbihzecbhribeo\ewrihtalizme.exe
- C:\jbihzecbhribeo\t6zvyomie
- %WINDIR%\jbihzecbhribeo\cuyfghg
- C:\jbihzecbhribeo\cuyfghg
- C:\jbihzecbhribeo\mpm2qcswhojeyp3.exe
- C:\jbihzecbhribeo\ewrihtalizme.exe
- C:\jbihzecbhribeo\lmtnzkavp.exe
- C:\jbihzecbhribeo\mpm2qcswhojeyp3.exe
- %WINDIR%\jbihzecbhribeo\cuyfghg
- %WINDIR%\jbihzecbhribeo\cuyfghg
- '18#.#21.242.79':46084
- '20#.#23.152.97':27682
- '19#.#6.240.249':21875
- '79.##3.139.198':21201
- '87.##.238.184':44724
- '82.##7.164.91':40801
- '74.#5.64.25':22739
- '12#.#60.112.138':27440
- ClassName: 'Shell_TrayWnd' WindowName: ''