Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Installer Compatibility Collector' = 'C:\nwnuatogdbo\iylwunzhlv.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Shadow Scheduler Auto Transfer Reporting RPC] 'ImagePath' = 'C:\nwnuatogdbo\iylwunzhlv.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Shadow Scheduler Auto Transfer Reporting RPC] 'Start' = '00000002'
- 'C:\nwnuatogdbo\dztbqinzrm.exe' "c:\nwnuatogdbo\iylwunzhlv.exe"
- 'C:\nwnuatogdbo\iylwunzhlv.exe'
- 'C:\nwnuatogdbo\u5ypf2tqbzwwwhqino4rw.exe'
- C:\nwnuatogdbo\iylwunzhlv.exe
- C:\nwnuatogdbo\dztbqinzrm.exe
- C:\nwnuatogdbo\jkpdmb
- %WINDIR%\nwnuatogdbo\marxvsn
- C:\nwnuatogdbo\marxvsn
- C:\nwnuatogdbo\u5ypf2tqbzwwwhqino4rw.exe
- C:\nwnuatogdbo\dztbqinzrm.exe
- C:\nwnuatogdbo\iylwunzhlv.exe
- C:\nwnuatogdbo\u5ypf2tqbzwwwhqino4rw.exe
- %WINDIR%\nwnuatogdbo\marxvsn
- %WINDIR%\nwnuatogdbo\marxvsn
- '15#.#82.245.137':33982
- '22#.#1.110.45':48008
- '95.##.58.101':23245
- '79.##3.139.198':21201
- '10#.#4.136.243':42581
- '24.##9.216.168':33794
- '78.##5.171.93':23699
- '20#.#36.131.186':52293
- '87.##.238.184':44724
- '61.##6.2.217':25840
- '18#.#50.153.254':32097
- ClassName: 'Shell_TrayWnd' WindowName: ''