Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'tnp6hvg7.exe' = '%APPDATA%\tnp6hvg7.exe'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1406' = '00000000'
- %APPDATA%\25n89v6dxchrghc4.dat
- %APPDATA%\tnp6hvg7.exe
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012025020920250210\index.dat
- 'to###.#p2location.com':80
- 'to###.#p2location.com':443
- http://to###.#p2location.com/ib2/
- 'to###.#p2location.com':443
- DNS ASK cn####ayghmf.com
- DNS ASK to###.#p2location.com
- DNS ASK np####ibfocp.com
- DNS ASK gz####botlbg.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%APPDATA%\tnp6hvg7.exe'