Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'ajhlp' = 'xrapecqjsihinnic.exe .'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'rzwz' = '%TEMP%\xrapecqjsihinnic.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'ajhlp' = '%TEMP%\yvhzrsjfrkmqybzwtxc.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'rzwz' = 'yvhzrsjfrkmqybzwtxc.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'ajhlp' = 'ljwpikczmgjoxbaywbhf.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'ertbjahtv' = '%TEMP%\ljwpikczmgjoxbaywbhf.exe .'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'yjjpvkp' = 'ljwpikczmgjoxbaywbhf.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'krn' = '%TEMP%\aznhbexvjeioyddcbhonb.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'nzahoekv' = 'ezjzpodxhyyaghdyt.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'lvuzes' = 'xrapecqjsihinnic.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'ajhlp' = '%TEMP%\ezjzpodxhyyaghdyt.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'lvuzes' = 'ljwpikczmgjoxbaywbhf.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'rzwz' = '%TEMP%\ezjzpodxhyyaghdyt.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'ertbjahtv' = '%TEMP%\aznhbexvjeioyddcbhonb.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'krn' = '%TEMP%\ljwpikczmgjoxbaywbhf.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'ertbjahtv' = '%TEMP%\ezjzpodxhyyaghdyt.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'rzwz' = 'ljwpikczmgjoxbaywbhf.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'rzwz' = '%TEMP%\yvhzrsjfrkmqybzwtxc.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'ajhlp' = 'yvhzrsjfrkmqybzwtxc.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'ajhlp' = 'njulccsnyqrubdawsv.exe .'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'nzahoekv' = 'yvhzrsjfrkmqybzwtxc.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'xloxgygtwg' = '%TEMP%\njulccsnyqrubdawsv.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'yjjpvkp' = 'njulccsnyqrubdawsv.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'xloxgygtwg' = '%TEMP%\aznhbexvjeioyddcbhonb.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'ajhlp' = '%TEMP%\njulccsnyqrubdawsv.exe .'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'yjjpvkp' = 'aznhbexvjeioyddcbhonb.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'krn' = '%TEMP%\yvhzrsjfrkmqybzwtxc.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'rzwz' = 'aznhbexvjeioyddcbhonb.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'ertbjahtv' = '%TEMP%\njulccsnyqrubdawsv.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'xloxgygtwg' = '%TEMP%\xrapecqjsihinnic.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'ajhlp' = '%TEMP%\xrapecqjsihinnic.exe .'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'ajhlp' = '%TEMP%\ljwpikczmgjoxbaywbhf.exe .'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'rzwz' = '%TEMP%\njulccsnyqrubdawsv.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'krn' = '%TEMP%\xrapecqjsihinnic.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'rzwz' = 'xrapecqjsihinnic.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'yjjpvkp' = 'ezjzpodxhyyaghdyt.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'lvuzes' = 'yvhzrsjfrkmqybzwtxc.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'ajhlp' = 'ezjzpodxhyyaghdyt.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'ertbjahtv' = '%TEMP%\yvhzrsjfrkmqybzwtxc.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'ajhlp' = 'aznhbexvjeioyddcbhonb.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'rzwz' = 'ezjzpodxhyyaghdyt.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'Explorer.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'lvuzes' = 'njulccsnyqrubdawsv.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'xloxgygtwg' = '%TEMP%\ljwpikczmgjoxbaywbhf.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'nzahoekv' = 'aznhbexvjeioyddcbhonb.exe .'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'yjjpvkp' = 'yvhzrsjfrkmqybzwtxc.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'nzahoekv' = 'ljwpikczmgjoxbaywbhf.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'lvuzes' = 'ezjzpodxhyyaghdyt.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'yjjpvkp' = 'xrapecqjsihinnic.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'xloxgygtwg' = '%TEMP%\ezjzpodxhyyaghdyt.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'krn' = '%TEMP%\njulccsnyqrubdawsv.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'rzwz' = '%TEMP%\aznhbexvjeioyddcbhonb.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'nzahoekv' = 'njulccsnyqrubdawsv.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'lvuzes' = 'aznhbexvjeioyddcbhonb.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'ertbjahtv' = '%TEMP%\xrapecqjsihinnic.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'xloxgygtwg' = '%TEMP%\yvhzrsjfrkmqybzwtxc.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'nzahoekv' = 'xrapecqjsihinnic.exe .'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'krn' = '%TEMP%\ezjzpodxhyyaghdyt.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'rzwz' = 'njulccsnyqrubdawsv.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'ajhlp' = '%TEMP%\aznhbexvjeioyddcbhonb.exe .'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'rzwz' = '%TEMP%\ljwpikczmgjoxbaywbhf.exe'
- скрытых файлов
- Редактора реестра (RegEdit)
- Средство контроля пользовательских учетных записей (UAC)
- %TEMP%\yjjpvkp.exe "-"
- %PROGRAM_FILES%\oflxjepflyusurjarpoflxjepflyusurjar.ofl
- <SYSTEM32>\oflxjepflyusurjarpoflxjepflyusurjar.ofl
- <LS_APPDATA>\oflxjepflyusurjarpoflxjepflyusurjar.ofl
- %TEMP%\oflxjepflyusurjarpoflxjepflyusurjar.ofl
- %WINDIR%\oflxjepflyusurjarpoflxjepflyusurjar.ofl
- %TEMP%\flghissxsufsjvciobpvqrsc.hce
- <SYSTEM32>\flghissxsufsjvciobpvqrsc.hce
- %TEMP%\yjjpvkp.exe
- %PROGRAM_FILES%\flghissxsufsjvciobpvqrsc.hce
- %WINDIR%\flghissxsufsjvciobpvqrsc.hce
- <LS_APPDATA>\flghissxsufsjvciobpvqrsc.hce
- %PROGRAM_FILES%\oflxjepflyusurjarpoflxjepflyusurjar.ofl
- <SYSTEM32>\oflxjepflyusurjarpoflxjepflyusurjar.ofl
- <LS_APPDATA>\oflxjepflyusurjarpoflxjepflyusurjar.ofl
- %TEMP%\oflxjepflyusurjarpoflxjepflyusurjar.ofl
- %WINDIR%\oflxjepflyusurjarpoflxjepflyusurjar.ofl
- %PROGRAM_FILES%\flghissxsufsjvciobpvqrsc.hce
- <SYSTEM32>\flghissxsufsjvciobpvqrsc.hce
- <LS_APPDATA>\flghissxsufsjvciobpvqrsc.hce
- %TEMP%\flghissxsufsjvciobpvqrsc.hce
- %WINDIR%\flghissxsufsjvciobpvqrsc.hce
- '74.##5.232.51':80
- '67.##5.160.76':80
- '<IP-адрес в локальной сети>':80
- 'www.yo##ube.com':80
- 'www.bl##ger.com':80
- 'www.im##.com':80
- 'www.eb##.com':80
- 'www.fa###ook.com':80
- 'www.ad##e.com':80
- '<IP-адрес в локальной сети>':139
- 'www.wh###smyip.com':80
- 'www.wh###smyip.ca':80
- 'wh#####yip.everdot.org':80
- 'wh#####yipaddress.com':80
- 'www.sh####ipaddress.com':80
- 'www.bb#.co.uk':80
- '<IP-адрес в локальной сети>':445
- 'www.ba##u.com':80
- 'www.wi###edia.org':80
- 67.##5.160.76/
- www.bl##ger.com/
- www.yo##ube.com/
- 74.##5.232.51/
- www.im##.com/
- www.eb##.com/
- www.fa###ook.com/
- www.ad##e.com/
- www.wh###smyip.com/
- www.wh###smyip.ca/
- wh#####yip.everdot.org/
- wh#####yipaddress.com/
- www.wi###edia.org/
- www.bb#.co.uk/
- www.sh####ipaddress.com/
- www.ba##u.com/
- DNS ASK www.ya##o.com
- DNS ASK www.bl##ger.com
- DNS ASK www.yo##ube.com
- DNS ASK www.google.com
- DNS ASK www.im##.com
- DNS ASK www.eb##.com
- DNS ASK www.fa###ook.com
- DNS ASK www.ad##e.com
- DNS ASK www.wh###smyip.com
- DNS ASK www.wh###smyip.ca
- DNS ASK wh#####yip.everdot.org
- DNS ASK wh#####yipaddress.com
- DNS ASK www.wi###edia.org
- DNS ASK www.bb#.co.uk
- DNS ASK www.sh####ipaddress.com
- DNS ASK www.ba##u.com
- ClassName: '' WindowName: ''
- ClassName: 'Indicator' WindowName: ''