Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'Explorer.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'aofytldeylgycqvobem' = '%TEMP%\gshyrhxwozsikwzqb.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'ryiuiteylrfq' = '%TEMP%\pcskevmmfrlcfswoac.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'ramaqdqmbjzmlu' = '%TEMP%\cslgdxruqfcwcszujoyrs.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'ramaqdqmbjzmlu' = 'ncuokdwythdwbqwqeirj.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'uergxlzwmvmaakl' = 'zkyogvkizjbqrceu.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'gshyrhxwozsikwzqb' = 'gshyrhxwozsikwzqb.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'aofytldeylgycqvobem' = '%TEMP%\ncuokdwythdwbqwqeirj.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'pcskevmmfrlcfswoac' = '%TEMP%\zkyogvkizjbqrceu.exe .'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'qyjwlxjeszoay' = '%TEMP%\aofytldeylgycqvobem.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'gshyrhxwozsikwzqb' = 'ncuokdwythdwbqwqeirj.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'pcskevmmfrlcfswoac' = '%TEMP%\ncuokdwythdwbqwqeirj.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'ryiuiteylrfq' = '%TEMP%\ncuokdwythdwbqwqeirj.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'ramaqdqmbjzmlu' = '%TEMP%\gshyrhxwozsikwzqb.exe .'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'qyjwlxjeszoay' = '%TEMP%\gshyrhxwozsikwzqb.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'ramaqdqmbjzmlu' = '%TEMP%\pcskevmmfrlcfswoac.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'qyjwlxjeszoay' = 'pcskevmmfrlcfswoac.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'zkyogvkizjbqrceu' = 'ncuokdwythdwbqwqeirj.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'uergxlzwmvmaakl' = 'gshyrhxwozsikwzqb.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'zkyogvkizjbqrceu' = 'gshyrhxwozsikwzqb.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'qyjwlxjeszoay' = '%TEMP%\cslgdxruqfcwcszujoyrs.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'pcskevmmfrlcfswoac' = '%TEMP%\aofytldeylgycqvobem.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'qyjwlxjeszoay' = 'cslgdxruqfcwcszujoyrs.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'qyjwlxjeszoay' = 'ncuokdwythdwbqwqeirj.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'gshyrhxwozsikwzqb' = 'cslgdxruqfcwcszujoyrs.exe .'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'gshyrhxwozsikwzqb' = 'aofytldeylgycqvobem.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'ramaqdqmbjzmlu' = 'zkyogvkizjbqrceu.exe .'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'qyjwlxjeszoay' = '%TEMP%\pcskevmmfrlcfswoac.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'ramaqdqmbjzmlu' = 'cslgdxruqfcwcszujoyrs.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'qyjwlxjeszoay' = 'zkyogvkizjbqrceu.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'ramaqdqmbjzmlu' = 'gshyrhxwozsikwzqb.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'uergxlzwmvmaakl' = 'ncuokdwythdwbqwqeirj.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'zkyogvkizjbqrceu' = 'cslgdxruqfcwcszujoyrs.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'gshyrhxwozsikwzqb' = 'zkyogvkizjbqrceu.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'aofytldeylgycqvobem' = '%TEMP%\zkyogvkizjbqrceu.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'pcskevmmfrlcfswoac' = '%TEMP%\gshyrhxwozsikwzqb.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'ryiuiteylrfq' = '%TEMP%\aofytldeylgycqvobem.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'qyjwlxjeszoay' = '%TEMP%\zkyogvkizjbqrceu.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'ramaqdqmbjzmlu' = '%TEMP%\zkyogvkizjbqrceu.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'qyjwlxjeszoay' = 'aofytldeylgycqvobem.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'uergxlzwmvmaakl' = 'pcskevmmfrlcfswoac.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'ryiuiteylrfq' = '%TEMP%\gshyrhxwozsikwzqb.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'zkyogvkizjbqrceu' = 'zkyogvkizjbqrceu.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'aofytldeylgycqvobem' = '%TEMP%\pcskevmmfrlcfswoac.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'pcskevmmfrlcfswoac' = '%TEMP%\cslgdxruqfcwcszujoyrs.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'ryiuiteylrfq' = '%TEMP%\zkyogvkizjbqrceu.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'qyjwlxjeszoay' = '%TEMP%\ncuokdwythdwbqwqeirj.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'ramaqdqmbjzmlu' = '%TEMP%\ncuokdwythdwbqwqeirj.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'qyjwlxjeszoay' = 'gshyrhxwozsikwzqb.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'ramaqdqmbjzmlu' = 'aofytldeylgycqvobem.exe .'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'gshyrhxwozsikwzqb' = 'pcskevmmfrlcfswoac.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'aofytldeylgycqvobem' = '%TEMP%\cslgdxruqfcwcszujoyrs.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'pcskevmmfrlcfswoac' = '%TEMP%\pcskevmmfrlcfswoac.exe .'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'zkyogvkizjbqrceu' = 'aofytldeylgycqvobem.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'ramaqdqmbjzmlu' = '%TEMP%\aofytldeylgycqvobem.exe .'
- скрытых файлов
- Редактора реестра (RegEdit)
- Средство контроля пользовательских учетных записей (UAC)
- %TEMP%\achoxdj.exe
- %WINDIR%\syswow64\dywwyxwefzbalgssmwljpp.yww
- %ProgramFiles(x86)%\dywwyxwefzbalgssmwljpp.yww
- %LOCALAPPDATA%\dywwyxwefzbalgssmwljpp.yww
- %WINDIR%\dywwyxwefzbalgssmwljpp.yww
- %TEMP%\dywwyxwefzbalgssmwljpp.yww
- %WINDIR%\syswow64\uajuhrbuglyiekhsxssbsdcircpzjcotg.msp
- %ProgramFiles(x86)%\uajuhrbuglyiekhsxssbsdcircpzjcotg.msp
- %LOCALAPPDATA%\uajuhrbuglyiekhsxssbsdcircpzjcotg.msp
- %WINDIR%\uajuhrbuglyiekhsxssbsdcircpzjcotg.msp
- %TEMP%\uajuhrbuglyiekhsxssbsdcircpzjcotg.msp
- %WINDIR%\syswow64\dywwyxwefzbalgssmwljpp.yww
- %ProgramFiles(x86)%\dywwyxwefzbalgssmwljpp.yww
- %LOCALAPPDATA%\dywwyxwefzbalgssmwljpp.yww
- %WINDIR%\dywwyxwefzbalgssmwljpp.yww
- %TEMP%\dywwyxwefzbalgssmwljpp.yww
- %WINDIR%\syswow64\uajuhrbuglyiekhsxssbsdcircpzjcotg.msp
- %ProgramFiles(x86)%\uajuhrbuglyiekhsxssbsdcircpzjcotg.msp
- %LOCALAPPDATA%\uajuhrbuglyiekhsxssbsdcircpzjcotg.msp
- %WINDIR%\uajuhrbuglyiekhsxssbsdcircpzjcotg.msp
- %TEMP%\uajuhrbuglyiekhsxssbsdcircpzjcotg.msp
- 'wh#####yipaddress.com':80
- 'sh####ipaddress.com':80
- 'wh###smyip.com':80
- 'yo##ube.com':80
- '<LOCALNET>.28.2':445
- '<LOCALNET>.28.2':139
- 'qs##ii.org':80
- http://wh#####yipaddress.com/
- http://www.sh####ipaddress.com/
- http://www.wh###smyip.com/
- http://www.yo##ube.com/
- DNS ASK jp####jraoqj.net
- DNS ASK bd####ecjob.info
- DNS ASK ps###aj.info
- DNS ASK lm###qizltz.net
- DNS ASK sw###kwmjdd.net
- DNS ASK uo###aki.com
- DNS ASK wx####xiqjnc.info
- DNS ASK du####dqrkb.info
- DNS ASK af###ahytnc.net
- DNS ASK ha###tcbzy.net
- DNS ASK sy###wgl.info
- DNS ASK jq###mhov.com
- DNS ASK qs##ii.org
- DNS ASK bv###yppza.info
- DNS ASK rw###kbuh.info
- DNS ASK oy####litzr.info
- DNS ASK ec###syq.org
- DNS ASK re###arxnl.info
- DNS ASK ei###enn.net
- DNS ASK rn###obcdw.info
- DNS ASK tw####jyxyv.info
- DNS ASK bu###kjie.com
- DNS ASK sh####ipaddress.com
- DNS ASK wh###smyip.com
- DNS ASK yo##ube.com
- DNS ASK xg##ree.com
- DNS ASK zi###vno.net
- DNS ASK tm##yg.net
- DNS ASK hl##cio.org
- DNS ASK kn###unqhc.net
- DNS ASK zz###try.net
- DNS ASK ew###qqgx.net
- DNS ASK is###imgwa.com
- DNS ASK bi##nyw.org
- DNS ASK vy####norvhq.net
- DNS ASK mg##ue.com
- DNS ASK sb####welmb.info
- DNS ASK wh#####yip.everdot.org
- DNS ASK to###mcbl.info
- DNS ASK wh#####yipaddress.com
- DNS ASK wh###smyip.ca
- 'localhost':55235
- 'localhost':60068
- '%TEMP%\achoxdj.exe' "-"