Техническая информация
- [HKLM\System\CurrentControlSet\Services\qnlflpkof] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\qnlflpkof] 'ImagePath' = '<SYSTEM32>\routes.exe qnlflpkof'
- 'qnlflpkof' <SYSTEM32>\routes.exe qnlflpkof
- %WINDIR%\syswow64\routes.exe
- из <Полный путь к файлу> в %WINDIR%\syswow64\wostmp\_1294759995_1207752111
- '1.###.248.27':27930
- '<LOCALNET>.49.0':27930
- '14.#92.2.37':27930
- '<LOCALNET>.49.1':27930
- '<LOCALNET>.49.2':27930
- '10#.#1.194.192':16800
- '<LOCALNET>.49.3':27930
- '<LOCALNET>.49.3':64324
- '17#.16.8.50':27930
- '17#.16.8.40':27930
- '17#.#6.48.221':27930
- '17#.#6.12.203':27930
- '10#.#16.52.20':27930
- '%WINDIR%\syswow64\routes.exe' qnlflpkof