Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'NGEN COM+ HomeGroup Location' = 'C:\atxnvcwjiai\xeudflk.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Shadow Performance Secure Sharing Portable Policy] 'ImagePath' = 'C:\atxnvcwjiai\xeudflk.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Shadow Performance Secure Sharing Portable Policy] 'Start' = '00000002'
- 'C:\atxnvcwjiai\ihtgemy.exe' "c:\atxnvcwjiai\xeudflk.exe"
- 'C:\atxnvcwjiai\xeudflk.exe'
- 'C:\atxnvcwjiai\vmlp2lz8jojjgdzrclm.exe'
- C:\atxnvcwjiai\xeudflk.exe
- C:\atxnvcwjiai\ihtgemy.exe
- C:\atxnvcwjiai\sx1wfntku
- %WINDIR%\atxnvcwjiai\jdbhm85qz
- C:\atxnvcwjiai\jdbhm85qz
- C:\atxnvcwjiai\vmlp2lz8jojjgdzrclm.exe
- C:\atxnvcwjiai\ihtgemy.exe
- C:\atxnvcwjiai\xeudflk.exe
- C:\atxnvcwjiai\vmlp2lz8jojjgdzrclm.exe
- %WINDIR%\atxnvcwjiai\jdbhm85qz
- %WINDIR%\atxnvcwjiai\jdbhm85qz
- '10#.#02.79.27':36272
- '94.##1.114.138':44254
- '21#.#07.110.82':26314
- '18#.#50.153.254':32097
- '20#.#36.131.186':52293
- '20#.#7.225.58':33073
- '93.##7.67.155':25640
- '86.##5.19.130':27743
- '5.##.19.242':27426
- '5.##.147.5':26337
- '41.##.10.183':48405
- ClassName: 'Shell_TrayWnd' WindowName: ''