Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Files Credential User Call Peer' = 'C:\bvypaplcnk\ukmruwq.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\AuthIP Modules Presentation] 'ImagePath' = 'C:\bvypaplcnk\ukmruwq.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\AuthIP Modules Presentation] 'Start' = '00000002'
- 'C:\bvypaplcnk\voivrdem.exe' "c:\bvypaplcnk\ukmruwq.exe"
- 'C:\bvypaplcnk\ukmruwq.exe'
- 'C:\bvypaplcnk\tq0ug2qvwqkqoeyqycz8u.exe'
- C:\bvypaplcnk\ukmruwq.exe
- C:\bvypaplcnk\voivrdem.exe
- C:\bvypaplcnk\czllik3x
- %WINDIR%\bvypaplcnk\cycrqjfs
- C:\bvypaplcnk\cycrqjfs
- C:\bvypaplcnk\tq0ug2qvwqkqoeyqycz8u.exe
- C:\bvypaplcnk\voivrdem.exe
- C:\bvypaplcnk\ukmruwq.exe
- C:\bvypaplcnk\tq0ug2qvwqkqoeyqycz8u.exe
- %WINDIR%\bvypaplcnk\cycrqjfs
- %WINDIR%\bvypaplcnk\cycrqjfs
- 'po####lethird.net':80
- 'mo####inobject.net':80
- 'mo####inthird.net':80
- 'mo####instation.net':80
- 'po####lestation.net':80
- http://po####lethird.net/index.php
- http://mo####inobject.net/index.php
- http://mo####inthird.net/index.php
- http://mo####instation.net/index.php
- http://po####lestation.net/index.php
- DNS ASK po####lethird.net
- DNS ASK mo####inobject.net
- DNS ASK po####leobject.net
- DNS ASK mo####instation.net
- DNS ASK po####lestation.net
- DNS ASK mo####inthird.net
- ClassName: 'Shell_TrayWnd' WindowName: ''