Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '{1D476073-5E7F-AD41-B897-60D4A63F43C6}' = '"%APPDATA%\Nyejk\lowa.exe"'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DisableNotifications' = '00000001'
- %APPDATA%\Nyejk\lowa.exe
- <Служебный элемент>
- %TEMP%\tmpec58e7f0.bat
- <LS_APPDATA>\ehnooc.ett
- %APPDATA%\Nyejk\lowa.exe
- '46.#9.20.69':15320
- '18#.#41.14.25':17107
- '99.##.197.178':15336
- '31.##2.27.193':16556
- '77.##2.58.208':24916
- '75.##2.169.226':24477
- '18#.#7.206.230':25561
- '77.##.237.45':12541
- '95.##4.97.119':15698
- ClassName: 'Indicator' WindowName: ''