Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'svpgxke' = '%ALLUSERSPROFILE%\Tencent\wnyovcthrlvpzgnfhyipovcjqxoyfmtasdxbypjanoympdnyymzgkosmt\svpgxke.exe'
- %ALLUSERSPROFILE%\tencent\wnyovcthrlvpzgnfhyipovcjqxoyfmtasdxbypjanoympdnyymzgkosmt\svpgxke.txt
- %ALLUSERSPROFILE%\tencent\wnyovcthrlvpzgnfhyipovcjqxoyfmtasdxbypjanoympdnyymzgkosmt\ctxmui.dll
- %ALLUSERSPROFILE%\tencent\wnyovcthrlvpzgnfhyipovcjqxoyfmtasdxbypjanoympdnyymzgkosmt\svpgxke.exe
- %LOCALAPPDATA%\178bfbff000406f1
- %ALLUSERSPROFILE%\tencent\wnyovcthrlvpzgnfhyipovcjqxoyfmtasdxbypjanoympdnyymzgkosmt\key
- <Полный путь к файлу> в %TEMP%\89d65e5a-58cc-484f-b1b9-64849e61c996\....\temporaryfile
- '15#.#5.135.37':8080
- '15#.#5.135.37':12345
- http://15#.##.135.37:8080/9x.dll via 15#.#5.135.37
- '15#.#5.135.37':12345
- '%ALLUSERSPROFILE%\tencent\wnyovcthrlvpzgnfhyipovcjqxoyfmtasdxbypjanoympdnyymzgkosmt\svpgxke.exe'
- '%WINDIR%\syswow64\cmd.exe' /c start %ALLUSERSPROFILE%\Tencent\wnyovcthrlvpzgnfhyipovcjqxoyfmtasdxbypjanoympdnyymzgkosmt\svpgxke.exe' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c start %ALLUSERSPROFILE%\Tencent\wnyovcthrlvpzgnfhyipovcjqxoyfmtasdxbypjanoympdnyymzgkosmt\svpgxke.exe