Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\Print Modules Copy Storage Color SPP Shadow] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Print Modules Copy Storage Color SPP Shadow] 'ImagePath' = 'C:\ntcdjhent\uxqhpzamd.exe'
- 'Print Modules Copy Storage Color SPP Shadow' C:\ntcdjhent\uxqhpzamd.exe
- %WINDIR%\ntcdjhent\zmdmvkyfli
- C:\ntcdjhent\zmdmvkyfli
- C:\ntcdjhent\n2yipbxjvhvg4xbmz.exe
- C:\ntcdjhent\uxqhpzamd.exe
- C:\ntcdjhent\zubgerpqdqs.exe
- C:\ntcdjhent\qrlq0je
- C:\ntcdjhent\uxqhpzamd.exe
- C:\ntcdjhent\zubgerpqdqs.exe
- %WINDIR%\ntcdjhent\zmdmvkyfli
- C:\ntcdjhent\n2yipbxjvhvg4xbmz.exe
- %WINDIR%\ntcdjhent\zmdmvkyfli
- '12#.#60.112.138':27440
- '15#.#82.245.137':33982
- '86.##5.219.12':21375
- '19#.#54.74.242':31770
- '19#.#47.86.10':25432
- '80.#4.199.6':49579
- '87.##.238.184':44724
- 'C:\ntcdjhent\n2yipbxjvhvg4xbmz.exe'
- 'C:\ntcdjhent\uxqhpzamd.exe'
- 'C:\ntcdjhent\zubgerpqdqs.exe' "c:\ntcdjhent\uxqhpzamd.exe"