Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\lbalxtuu.kpj] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\lbalxtuu.kpj] 'ImagePath' = '%WINDIR%\SysWOW64\regsvr32.exe /s "%WINDIR%\SysWOW64\Nwxptsyzwdzesqw\lbalxtuu.kpj"'
- 'lbalxtuu.kpj' %WINDIR%\SysWOW64\regsvr32.exe /s "%WINDIR%\SysWOW64\Nwxptsyzwdzesqw\lbalxtuu.kpj"
- %ALLUSERSPROFILE%\ывацыяпцувкопю.цвычир
- %ALLUSERSPROFILE%\ывацыяпцувкопю.цвычир в %WINDIR%\syswow64\nwxptsyzwdzesqw\lbalxtuu.kpj
- '51.#1.76.89':8080
- '17#.#54.208.91':8080
- '14#.#6.128.192':443
- '12#.#0.40.183':80
- '16#.#6.218.63':8080
- '51.#1.76.89':8080
- '14#.#6.128.192':443
- '%WINDIR%\syswow64\cmd.exe' regsvr32 %ALLUSERSPROFILE%\ывацыяпцувкопю.цвычир
- '%WINDIR%\syswow64\regsvr32.exe' %ALLUSERSPROFILE%\ывацыяпцувкопю.цвычир
- '%WINDIR%\syswow64\regsvr32.exe' /s "%WINDIR%\SysWOW64\Nwxptsyzwdzesqw\lbalxtuu.kpj"