Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Function Tracking Routing Helper DNS Trap' = 'C:\lwxgnlutewkop\ryaiirq.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Adaptive Networking Volume] 'ImagePath' = 'C:\lwxgnlutewkop\ryaiirq.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Adaptive Networking Volume] 'Start' = '00000002'
- 'C:\lwxgnlutewkop\tkosyjnkvuj.exe' "c:\lwxgnlutewkop\ryaiirq.exe"
- 'C:\lwxgnlutewkop\ryaiirq.exe'
- 'C:\lwxgnlutewkop\h8v62o05riukgzps4t.exe'
- C:\lwxgnlutewkop\ryaiirq.exe
- C:\lwxgnlutewkop\tkosyjnkvuj.exe
- C:\lwxgnlutewkop\wotjuvhezt
- %WINDIR%\lwxgnlutewkop\ln24lvw
- C:\lwxgnlutewkop\ln24lvw
- C:\lwxgnlutewkop\h8v62o05riukgzps4t.exe
- C:\lwxgnlutewkop\tkosyjnkvuj.exe
- C:\lwxgnlutewkop\ryaiirq.exe
- C:\lwxgnlutewkop\h8v62o05riukgzps4t.exe
- %WINDIR%\lwxgnlutewkop\ln24lvw
- %WINDIR%\lwxgnlutewkop\ln24lvw
- '10#.#02.79.27':36272
- '86.##5.19.130':27743
- '20#.#36.131.186':52293
- '17#.37.2.43':44303
- '87.##.238.184':44724
- '18#.#39.139.100':37599
- '87.##.38.225':33631
- '81.##4.87.112':37714
- '84.##8.128.25':27132
- '19#.#7.134.20':44965
- '61.##6.2.217':25840
- '82.##7.164.91':40801
- ClassName: 'Shell_TrayWnd' WindowName: ''