Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Web Services Extender Update' = 'C:\ahljnkrjzznuat\ykijtxebvhcd.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Host Removal Plug Tools Controls] 'ImagePath' = 'C:\ahljnkrjzznuat\ykijtxebvhcd.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Host Removal Plug Tools Controls] 'Start' = '00000002'
- 'C:\ahljnkrjzznuat\lpcyxfkkqv.exe' "c:\ahljnkrjzznuat\ykijtxebvhcd.exe"
- 'C:\ahljnkrjzznuat\ykijtxebvhcd.exe'
- 'C:\ahljnkrjzznuat\oaipz2odmogwwpzutnjxr.exe'
- C:\ahljnkrjzznuat\ykijtxebvhcd.exe
- C:\ahljnkrjzznuat\lpcyxfkkqv.exe
- C:\ahljnkrjzznuat\qllbxxjdam
- %WINDIR%\ahljnkrjzznuat\dfvqmdimyr
- C:\ahljnkrjzznuat\dfvqmdimyr
- C:\ahljnkrjzznuat\oaipz2odmogwwpzutnjxr.exe
- C:\ahljnkrjzznuat\lpcyxfkkqv.exe
- C:\ahljnkrjzznuat\ykijtxebvhcd.exe
- C:\ahljnkrjzznuat\oaipz2odmogwwpzutnjxr.exe
- %WINDIR%\ahljnkrjzznuat\dfvqmdimyr
- %WINDIR%\ahljnkrjzznuat\dfvqmdimyr
- '17#.37.2.43':44303
- '95.##.58.101':23245
- '10#.#29.186.201':47507
- '72.##1.207.62':22399
- '61.##6.2.217':25840
- '98.##.223.221':20922
- '78.##5.171.93':23699
- '21#.#65.0.136':35711
- '18#.#42.145.105':26662
- '87.##.238.184':44724
- '10#.#4.136.243':42581
- '19#.#7.134.20':44965
- '2.##.19.50':35833
- ClassName: 'Shell_TrayWnd' WindowName: ''