Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Engine Redirector Device Launcher Access' = '<SYSTEM32>\llipxwxi.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\llipxwxi.exe
- [<HKLM>\SYSTEM\ControlSet001\Services\IP BitLocker Reports Video Backup] 'Start' = '00000002'
- Центр обеспечения безопасности (Security Center)
- '<SYSTEM32>\qvhpixgfirkf.exe' "<SYSTEM32>\llipxwxi.exe"
- '%TEMP%\tqvdor4qjrkzasl.exe' -r 28254 tcp
- '%TEMP%\tqvdor28lhkzastbsupvrg.exe'
- '<SYSTEM32>\llipxwxi.exe'
- <SYSTEM32>\ctxoiyfx\run
- <SYSTEM32>\ctxoiyfx\rng
- %TEMP%\tqvdor4qjrkzasl.exe
- <SYSTEM32>\ctxoiyfx\cfg
- <SYSTEM32>\qvhpixgfirkf.exe
- %TEMP%\tqvdor28lhkzastbsupvrg.exe
- <SYSTEM32>\ctxoiyfx\tst
- <SYSTEM32>\llipxwxi.exe
- <SYSTEM32>\ctxoiyfx\etc
- <SYSTEM32>\qvhpixgfirkf.exe
- <SYSTEM32>\llipxwxi.exe
- %TEMP%\tqvdor4qjrkzasl.exe
- <DRIVERS>\etc\hosts
- %TEMP%\tqvdor28lhkzastbsupvrg.exe
- 'ga########all-talk-community.com':80
- ga########all-talk-community.com/forum/search.php?me#########################################
- DNS ASK go#####everytime.com
- DNS ASK el#####arimagine.com
- DNS ASK sp###hold.net
- DNS ASK ja###uter.com
- DNS ASK ga########all-talk-community.com
- DNS ASK sp###aguga.com
- DNS ASK do####club-grup.com
- '23#.#55.255.250':1900