Техническая информация
- [<HKCU>\SYSTEM\CurrentControlSet\Services\CBD19B7A] 'ImagePath' = '<SYSTEM32>\CBD19B7A.EXE -service'
- [<HKLM>\SYSTEM\ControlSet001\Services\CBD19B7A] 'ImagePath' = '<SYSTEM32>\CBD19B7A.EXE -service'
- [<HKLM>\SYSTEM\ControlSet001\Services\CBD19B7A] 'Start' = '00000002'
- <SYSTEM32>\6A1C6123.exe toni"89|d=ba&9=;"hed'fbvsjl.
- <SYSTEM32>\CBD19B7A.EXE -service
- <SYSTEM32>\cmd.exe /c <SYSTEM32>\delme.bat
- <SYSTEM32>\cmd.exe /c <SYSTEM32>\GoKaba.bat
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\winlogon.exe
- ClassName: 'AVP.Product_Notification' WindowName: '?????????????????? 6.0: ????'
- <SYSTEM32>\CBD19B7A.DLL
- <SYSTEM32>\delme.bat
- <SYSTEM32>\6A1C6123.exe
- <SYSTEM32>\GoKaba.bat
- <SYSTEM32>\CBD19B7A.EXE
- <SYSTEM32>\CBD19B7AT.EXE
- 'localhost':1035