Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'uqajfoxtdyhqm' = '%APPDATA%\qvfbktpyidm\irbwgpl.exe "%TEMP%\tcewma.exe" %LOCALAPPDATA%\T�'
- tcewma.exe
- %TEMP%\nsv81c.tmp
- %TEMP%\brracnfv.te
- %TEMP%\poocmej.n
- %TEMP%\tcewma.exe
- %APPDATA%\qvfbktpyidm\irbwgpl.exe
- 'localhost':56932
- '45.##8.234.54':56932
- 'ge###ugin.net':80
- http://ge###ugin.net/json.gp
- '45.##8.234.54':56932
- DNS ASK ge###ugin.net
- 'localhost':61922
- 'localhost':57319
- '%TEMP%\tcewma.exe' %TEMP%\poocmej.n
- '%TEMP%\tcewma.exe'