Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Resource Bus Files Security CardSpace UserMode' = 'C:\bfogwjqfjb\gsdhigjla.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Cache Scheduler Panel Office Manager NGEN Block] 'ImagePath' = 'C:\bfogwjqfjb\gsdhigjla.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Cache Scheduler Panel Office Manager NGEN Block] 'Start' = '00000002'
- 'C:\bfogwjqfjb\ddxjcuklvcf.exe' "c:\bfogwjqfjb\gsdhigjla.exe"
- 'C:\bfogwjqfjb\gsdhigjla.exe'
- 'C:\bfogwjqfjb\zr52t46cp5me2khvbu.exe'
- C:\bfogwjqfjb\gsdhigjla.exe
- C:\bfogwjqfjb\ddxjcuklvcf.exe
- C:\bfogwjqfjb\pzf59ll
- %WINDIR%\bfogwjqfjb\ol1upszdxhm
- C:\bfogwjqfjb\ol1upszdxhm
- C:\bfogwjqfjb\zr52t46cp5me2khvbu.exe
- C:\bfogwjqfjb\ddxjcuklvcf.exe
- C:\bfogwjqfjb\gsdhigjla.exe
- C:\bfogwjqfjb\zr52t46cp5me2khvbu.exe
- %WINDIR%\bfogwjqfjb\ol1upszdxhm
- %WINDIR%\bfogwjqfjb\ol1upszdxhm
- '88.#48.36.4':25752
- '87.##6.160.36':41347
- '18#.2.4.92':44843
- '79.##7.196.121':45688
- '18#.#72.215.47':51612
- '12#.#60.112.138':27440
- '87.##.238.184':44724
- '10#.#28.239.221':49777
- ClassName: 'Shell_TrayWnd' WindowName: ''