Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\zGqaxQfIXkoeRaV.dll] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\zGqaxQfIXkoeRaV.dll] 'ImagePath' = '<SYSTEM32>\regsvr32.exe "<SYSTEM32>\ZVLhDQzPxQvycAUH\zGqaxQfIXkoeRaV.dll"'
- 'zGqaxQfIXkoeRaV.dll' <SYSTEM32>\regsvr32.exe "<SYSTEM32>\ZVLhDQzPxQvycAUH\zGqaxQfIXkoeRaV.dll"
- из <Полный путь к файлу> в <SYSTEM32>\zvlhdqzpxqvycauh\zgqaxqfixkoerav.dll
- '17#.#05.70.96':443
- '15#.#5.66.124':8080
- '21#.#41.20.155':443
- '13#.#00.24.231':80
- '10#.50.0.91':8080
- '77.##.247.144':8080
- '18#.#.135.165':8080
- '20#.#26.98.206':8080
- '1.##4.2.232':8080
- '20#.#14.109.124':443
- '5.#.116.246':8080
- '14#.#9.226.45':443
- '20#.#4.166.162':443
- '18#.#.212.130':7080
- '15#.#5.66.124':8080
- '13#.#00.24.231':80
- '20#.#26.98.206':8080
- '20#.#14.109.124':443
- '14#.#9.226.45':443
- '<SYSTEM32>\regsvr32.exe' "<SYSTEM32>\ZVLhDQzPxQvycAUH\zGqaxQfIXkoeRaV.dll"