Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Framework Receiver IKE Awareness Protected' = 'C:\kplneeot\qxylppg.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Identity COM+ Audio Registry Event] 'ImagePath' = 'C:\kplneeot\qxylppg.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Identity COM+ Audio Registry Event] 'Start' = '00000002'
- 'C:\kplneeot\iezsrhmfgidf.exe' "c:\kplneeot\qxylppg.exe"
- 'C:\kplneeot\qxylppg.exe'
- 'C:\kplneeot\rsa3cxarcwiptgczoga.exe'
- C:\kplneeot\qxylppg.exe
- C:\kplneeot\iezsrhmfgidf.exe
- C:\kplneeot\wvsqpcl
- %WINDIR%\kplneeot\bp69trtbzq
- C:\kplneeot\bp69trtbzq
- C:\kplneeot\rsa3cxarcwiptgczoga.exe
- C:\kplneeot\iezsrhmfgidf.exe
- C:\kplneeot\qxylppg.exe
- C:\kplneeot\rsa3cxarcwiptgczoga.exe
- %WINDIR%\kplneeot\bp69trtbzq
- %WINDIR%\kplneeot\bp69trtbzq
- '18#.#22.43.28':46084
- '10#.#4.136.243':42581
- '88.#48.36.4':25752
- '77.##8.205.139':22969
- '86.##.69.232':41590
- '95.##8.241.220':49038
- '86.##5.19.130':27743
- '87.##.38.225':33631
- '12#.#60.123.173':36805
- '95.##.58.101':23245
- '72.##1.207.62':22399
- ClassName: 'Shell_TrayWnd' WindowName: ''