Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Workstation Search Security Interactive WMI' = 'C:\ivkofiomwvp\lxvbbousd.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Link DCOM Trap Computer] 'ImagePath' = 'C:\ivkofiomwvp\lxvbbousd.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Link DCOM Trap Computer] 'Start' = '00000002'
- 'C:\ivkofiomwvp\gzhilfv.exe' "c:\ivkofiomwvp\lxvbbousd.exe"
- 'C:\ivkofiomwvp\lxvbbousd.exe'
- 'C:\ivkofiomwvp\ysn3bwumhsnax6aasi.exe'
- C:\ivkofiomwvp\lxvbbousd.exe
- C:\ivkofiomwvp\gzhilfv.exe
- C:\ivkofiomwvp\nmu4jggda
- %WINDIR%\ivkofiomwvp\nfladedimm8
- C:\ivkofiomwvp\nfladedimm8
- C:\ivkofiomwvp\ysn3bwumhsnax6aasi.exe
- C:\ivkofiomwvp\gzhilfv.exe
- C:\ivkofiomwvp\lxvbbousd.exe
- C:\ivkofiomwvp\ysn3bwumhsnax6aasi.exe
- %WINDIR%\ivkofiomwvp\nfladedimm8
- %WINDIR%\ivkofiomwvp\nfladedimm8
- '77.##7.13.68':30018
- '10#.#29.186.201':47507
- '87.##.38.225':33631
- '19#.#6.240.249':21875
- '86.##5.19.130':27743
- '10#.#24.230.242':49777
- '81.##4.87.112':37714
- '24.##9.216.168':33794
- '20#.#23.152.97':27682
- ClassName: 'Shell_TrayWnd' WindowName: ''