Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'qxdrlww' = '"%APPDATA%\Microsoft\Lzapnmnmz\lzapnmnm.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'CTFMON.EXE' = '"%APPDATA%\Microsoft\Lzapnmnmz\lzapnmnm.exe" /c <SYSTEM32>\ctfmon.exe'
- <SYSTEM32>\cscript.exe
- %HOMEPATH%\jmmbmsmeerldunhouzodh.vbs
- %HOMEPATH%\jayotcpnuosjtpyqeuu.vbs
- %APPDATA%\Microsoft\Lzapnmnmz\lzapnmn.dat
- %HOMEPATH%\jmmbmsmeerldunhouzodh.vbs
- %HOMEPATH%\jayotcpnuosjtpyqeuu.vbs
- '%APPDATA%\Microsoft\Lzapnmnmz\lzapnmnm.exe'
- '<SYSTEM32>\cscript.exe' "%HOMEPATH%\jmmbmsmeerldunhouzodh.vbs"
- '<SYSTEM32>\cscript.exe' "%HOMEPATH%\jayotcpnuosjtpyqeuu.vbs"
- '<SYSTEM32>\mobsync.exe'