Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Collector AuthIP Publication Bus' = 'C:\taasfxdxikwfnt\wpxgdvkoor.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Panel Trap Name Group Function] 'ImagePath' = 'C:\taasfxdxikwfnt\wpxgdvkoor.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Panel Trap Name Group Function] 'Start' = '00000002'
- 'C:\taasfxdxikwfnt\divohrdr.exe' "c:\taasfxdxikwfnt\wpxgdvkoor.exe"
- 'C:\taasfxdxikwfnt\wpxgdvkoor.exe'
- 'C:\taasfxdxikwfnt\tfq1i2qdoakpoicmk.exe'
- C:\taasfxdxikwfnt\wpxgdvkoor.exe
- C:\taasfxdxikwfnt\divohrdr.exe
- C:\taasfxdxikwfnt\btsffbmix
- %WINDIR%\taasfxdxikwfnt\hvhr4or
- C:\taasfxdxikwfnt\hvhr4or
- C:\taasfxdxikwfnt\tfq1i2qdoakpoicmk.exe
- C:\taasfxdxikwfnt\divohrdr.exe
- C:\taasfxdxikwfnt\wpxgdvkoor.exe
- C:\taasfxdxikwfnt\tfq1i2qdoakpoicmk.exe
- %WINDIR%\taasfxdxikwfnt\hvhr4or
- %WINDIR%\taasfxdxikwfnt\hvhr4or
- '18#.#39.139.100':37599
- '10#.#46.77.146':33927
- '19#.#47.86.10':25432
- '11#.#18.187.28':42065
- '77.##8.205.139':22969
- '2.##.19.50':35833
- '12#.#60.123.173':36805
- '5.##.19.242':27426
- '18#.#22.43.28':46084
- '73.##.228.84':36884
- '95.##8.241.220':49038
- ClassName: 'Shell_TrayWnd' WindowName: ''