Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Port Services Cache Shadow' = 'C:\qazzbwpqewezr\yzwzvnnfwinb.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\List Intelligent Transfer Block] 'ImagePath' = 'C:\qazzbwpqewezr\yzwzvnnfwinb.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\List Intelligent Transfer Block] 'Start' = '00000002'
- 'C:\qazzbwpqewezr\ywvlcsfnjfd.exe' "c:\qazzbwpqewezr\yzwzvnnfwinb.exe"
- 'C:\qazzbwpqewezr\yzwzvnnfwinb.exe'
- 'C:\qazzbwpqewezr\dyzjp2phjxkvmvkuubc9q.exe'
- C:\qazzbwpqewezr\yzwzvnnfwinb.exe
- C:\qazzbwpqewezr\ywvlcsfnjfd.exe
- C:\qazzbwpqewezr\qu8e95bccvji
- %WINDIR%\qazzbwpqewezr\hizslqnwcz
- C:\qazzbwpqewezr\hizslqnwcz
- C:\qazzbwpqewezr\dyzjp2phjxkvmvkuubc9q.exe
- C:\qazzbwpqewezr\ywvlcsfnjfd.exe
- C:\qazzbwpqewezr\yzwzvnnfwinb.exe
- C:\qazzbwpqewezr\dyzjp2phjxkvmvkuubc9q.exe
- %WINDIR%\qazzbwpqewezr\hizslqnwcz
- %WINDIR%\qazzbwpqewezr\hizslqnwcz
- '15#.#82.245.137':33982
- '91.##.35.122':26126
- '61.##6.2.217':25840
- '18#.#55.19.91':30767
- '21#.#19.80.21':36542
- '12#.#60.112.138':27440
- '18#.#72.215.47':51612
- '37.##2.223.103':22969
- ClassName: 'Shell_TrayWnd' WindowName: ''