Техническая информация
- [HKLM\System\CurrentControlSet\Services\AutoConnect TPM NGEN UPnP] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\AutoConnect TPM NGEN UPnP] 'ImagePath' = 'C:\vcdikvfj\khmhgsmrve.exe'
- 'AutoConnect TPM NGEN UPnP' C:\vcdikvfj\khmhgsmrve.exe
- %WINDIR%\vcdikvfj\lrzygr9
- C:\vcdikvfj\lrzygr9
- C:\vcdikvfj\qkvlvdug0y0kricbj.exe
- C:\vcdikvfj\khmhgsmrve.exe
- C:\vcdikvfj\tktaswiuyrz.exe
- C:\vcdikvfj\l46iplzlf01r
- C:\vcdikvfj\khmhgsmrve.exe
- C:\vcdikvfj\tktaswiuyrz.exe
- %WINDIR%\vcdikvfj\lrzygr9
- C:\vcdikvfj\qkvlvdug0y0kricbj.exe
- %WINDIR%\vcdikvfj\lrzygr9
- '34.##9.100.209':443
- DNS ASK ge###ewheat.net
- DNS ASK he###anger.net
- DNS ASK ge###eanger.net
- DNS ASK he###always.net
- DNS ASK ge####always.net
- DNS ASK he###forest.net
- DNS ASK ge####forest.net
- DNS ASK va####swheat.net
- 'C:\vcdikvfj\qkvlvdug0y0kricbj.exe'
- 'C:\vcdikvfj\khmhgsmrve.exe'
- 'C:\vcdikvfj\tktaswiuyrz.exe' "c:\vcdikvfj\khmhgsmrve.exe"