Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] 'dtseqrxk' = '{70A65C37-E551-403A-90A4-4CEC5F2D5166}'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] 'mgxfebsq' = '{5573685F-2148-4963-862F-8E5C074CC6C1}'
- '%TEMP%\ac8zt2\mqgldfvo.exe' reg
- '%TEMP%\ac8zt2\efwl.exe' reeon
- '%TEMP%\ac8zt2\efwl.exe' %WINDIR%\mgxfebsq.dll mgxfebsq
- '%TEMP%\ac8zt2\efwl.exe' %WINDIR%\dtseqrxk.dll dtseqrxk
- '%WINDIR%\explorer.exe'
- '<SYSTEM32>\regsvr32.exe' /s fqbewlna.dll
- '<SYSTEM32>\regsvr32.exe' /s %WINDIR%\vmgspntbpfe.dll
- %WINDIR%\Explorer.EXE
- %WINDIR%\efwl.exe
- %WINDIR%\mqgldfvo.exe
- %WINDIR%\mgxfebsq.dll
- %TEMP%\nsj4.tmp.bat
- %TEMP%\nsj3.tmp\System.dll
- %WINDIR%\vmgspntbpfe.dll
- %TEMP%\ac8zt2\mqgldfvo.exe
- %TEMP%\ac8zt2\mgxfebsq.dll
- %TEMP%\nsj3.tmp\blowfish_d.dll
- %TEMP%\nse2.tmp
- %TEMP%\ac8zt2\install.bat
- %TEMP%\ac8zt2\efwl.exe
- %TEMP%\ac8zt2\vmgspntbpfe.dll
- %TEMP%\ac8zt2\vmgspntbpfe.dll
- %TEMP%\nsj3.tmp\blowfish_d.dll
- %TEMP%\nsj3.tmp\System.dll
- %TEMP%\ac8zt2\mqgldfvo.exe
- %TEMP%\ac8zt2\efwl.exe
- %TEMP%\ac8zt2\install.bat
- %TEMP%\ac8zt2\mgxfebsq.dll
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- ClassName: 'SystemTray_Main' WindowName: ''
- ClassName: 'CSCHiddenWindow' WindowName: ''
- ClassName: 'SysListView32' WindowName: ''
- ClassName: 'Proxy Desktop' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'BaseBar' WindowName: 'ChanApp'