Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\qhmblgkha] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\qhmblgkha] 'ImagePath' = '<SYSTEM32>\Protection.exe qhmblgkha'
- 'qhmblgkha' <SYSTEM32>\Protection.exe qhmblgkha
- <SYSTEM32>\protection.exe
- из <Полный путь к файлу> в <SYSTEM32>\wostmp\_1302335989_75494894
- '1.###.248.27':27930
- '<LOCALNET>..51.0':27930
- '<LOCALNET>..51.1':27930
- '14.#92.2.37':27930
- '<LOCALNET>..51.2':27930
- '<LOCALNET>..51.3':27930
- '<LOCALNET>..51.4':27930
- '<LOCALNET>..51.5':27930
- '10.#8.1.55':27930
- '<LOCALNET>..51.6':27930
- '<LOCALNET>..51.7':27930
- '<LOCALNET>..51.8':27930
- '<LOCALNET>..51.9':27930
- '10.#0.0.61':27930
- '<LOCALNET>..51.10':27930
- '<LOCALNET>..51.11':27930
- '<LOCALNET>..51.12':27930
- '<LOCALNET>..51.13':27930
- '10.#0.0.73':27930
- '<LOCALNET>..51.14':27930
- '<LOCALNET>..51.15':27930
- '<LOCALNET>..51.16':27930
- '<LOCALNET>..51.17':27930
- '10.#0.20.67':27930
- '<LOCALNET>..51.18':27930
- '<LOCALNET>..51.19':27930
- '<LOCALNET>..51.20':27930
- '<LOCALNET>..51.21':27930
- '10#.#16.52.20':27930
- '<LOCALNET>..51.22':27930
- '<LOCALNET>..51.23':27930
- '<LOCALNET>..51.24':27930
- '<LOCALNET>..51.25':27930
- '11#.#10.212.150':27930
- '<LOCALNET>..51.26':27930
- '<LOCALNET>..51.27':27930
- '<LOCALNET>..51.28':27930
- '<LOCALNET>..51.29':27930
- '<LOCALNET>..51.30':27930
- '12#.#60.154.252':27930
- '<LOCALNET>..51.31':27930
- '<LOCALNET>..51.32':27930
- '<LOCALNET>..51.33':27930
- '<LOCALNET>..51.34':27930
- '18#.#8.212.176':27930
- '<LOCALNET>..51.35':27930
- '<LOCALNET>..51.36':27930
- '<LOCALNET>..51.37':27930
- '<LOCALNET>..51.38':27930
- '18#.#1.63.214':27930
- '<LOCALNET>..51.39':27930
- '<LOCALNET>..51.40':27930
- '<LOCALNET>..51.41':27930
- '<LOCALNET>..51.42':27930
- '22#.#1.122.230':27930
- '<LOCALNET>..51.43':27930
- '<LOCALNET>..51.44':27930
- '<LOCALNET>..51.45':27930
- '<LOCALNET>..51.46':27930
- '58.##.147.71':27930
- '<LOCALNET>..51.47':27930
- '<LOCALNET>..51.48':27930
- '<LOCALNET>..51.49':27930
- '<LOCALNET>..51.50':27930
- '59.##.201.97':27930
- '<LOCALNET>..51.51':27930
- '<LOCALNET>..51.52':27930
- '<LOCALNET>..51.53':27930
- '<LOCALNET>..51.54':27930
- '<LOCALNET>..51.55':27930
- '61.##4.50.237':27930
- '<LOCALNET>..51.56':27930
- '<LOCALNET>..51.57':27930
- '<LOCALNET>..51.58':27930
- '<LOCALNET>..51.59':27930
- '82.##.198.189':27930
- '<LOCALNET>..51.60':27930
- '<LOCALNET>..51.61':27930
- '<LOCALNET>..51.62':27930
- '<LOCALNET>..51.63':27930
- '91.#87.99.3':27930
- '<LOCALNET>..51.64':27930
- '<LOCALNET>..51.65':27930
- '<LOCALNET>..51.66':27930
- '<LOCALNET>..51.67':27930
- '10#.#4.137.178':27930
- '<LOCALNET>..51.68':27930
- '<LOCALNET>..51.69':27930
- '<LOCALNET>..51.70':27930
- '<LOCALNET>..51.71':27930
- '11#.#93.17.179':27930
- '<LOCALNET>..51.72':27930
- '<LOCALNET>..51.73':27930
- '<LOCALNET>..51.74':27930
- '<LOCALNET>..51.75':27930
- '<LOCALNET>..51.76':27930
- '11#.#8.238.194':27930
- '<LOCALNET>..51.77':27930
- '<LOCALNET>..0.0':27930
- '<LOCALNET_GATEWAY>':27930
- '<LOCALNET>..51.78':27930
- '<LOCALNET>..0.2':27930
- '<LOCALNET>..51.79':27930
- '<LOCALNET>..0.3':27930
- '<LOCALNET>..51.80':27930
- '11#.#3.15.166':27930
- '<LOCALNET>..0.4':27930
- '<LOCALNET>..51.81':27930
- '<LOCALNET>..0.5':27930
- '<LOCALNET>..51.82':27930
- '<LOCALNET>..0.6':27930
- '<LOCALNET>..51.83':27930
- '<LOCALNET>..0.7':27930
- '11#.#19.252.204':27930
- '<LOCALNET>..51.84':27930
- '<LOCALNET>..0.8':27930
- '<LOCALNET>..51.85':27930
- '<LOCALNET>..0.9':27930
- '<LOCALNET>..51.86':27930
- '<LOCALNET>..0.10':27930
- '<LOCALNET>..51.87':27930
- '<LOCALNET>..0.11':27930
- '<LOCALNET>..51.88':27930
- '12#.#8.33.17':27930
- '<LOCALNET>..0.12':27930
- '<LOCALNET>..51.89':27930
- '<LOCALNET>..0.13':27930
- '<LOCALNET>..51.90':27930
- '<LOCALNET>..0.14':27930
- '<LOCALNET>..51.91':27930
- '<LOCALNET>..0.15':27930
- '<LOCALNET>..51.92':27930
- '<LOCALNET>..0.16':27930
- '12#.#47.83.95':27930
- '<LOCALNET>..51.93':27930
- '<LOCALNET>..0.17':27930
- '<LOCALNET>..51.94':27930
- '<LOCALNET>..0.18':27930
- '<LOCALNET>..51.95':27930
- '<LOCALNET>..0.19':27930
- '<LOCALNET>..51.96':27930
- '<LOCALNET>..0.20':27930
- '12#.#60.58.206':27930
- '<LOCALNET>..51.97':27930
- '<LOCALNET>..0.21':27930
- '<LOCALNET>..51.98':27930
- '<LOCALNET>..0.22':27930
- '<LOCALNET>..51.99':27930
- '<LOCALNET>..0.26':27930
- '<LOCALNET>..51.100':27930
- '<LOCALNET>..0.23':27930
- '16#.#94.189.141':27930
- '<LOCALNET>..0.24':27930
- '<LOCALNET>..51.101':27930
- '<LOCALNET>..0.25':27930
- '<LOCALNET>..51.102':27930
- '<LOCALNET>..0.30':27930
- '<LOCALNET>..51.103':27930
- '<LOCALNET>..0.27':27930
- '<LOCALNET>..51.104':27930
- '<LOCALNET>..0.28':27930
- '<LOCALNET>..51.105':27930
- '18#.#1.168.237':27930
- '<LOCALNET>..0.29':27930
- '<LOCALNET>..51.106':27930
- '<LOCALNET>..0.31':27930
- '<LOCALNET>..51.107':27930
- '<LOCALNET>..0.32':27930
- '<LOCALNET>..51.108':27930
- '<LOCALNET>..0.33':27930
- '<LOCALNET>..51.109':27930
- '18#.#2.131.182':27930
- '<LOCALNET>..0.34':27930
- '<LOCALNET>..51.110':27930
- '<LOCALNET>..0.35':27930
- '<LOCALNET>..51.111':27930
- '<LOCALNET>..0.36':27930
- '<LOCALNET>..51.112':27930
- '<LOCALNET>..0.37':27930
- '<LOCALNET>..51.113':27930
- '18#.#2.112.114':27930
- '<LOCALNET>..0.38':27930
- '<LOCALNET>..51.114':27930
- '<LOCALNET>..0.39':27930
- '<LOCALNET>..51.115':27930
- '<LOCALNET>..0.40':27930
- '<LOCALNET>..51.116':27930
- '<LOCALNET>..0.41':27930
- '<LOCALNET>..51.117':27930
- '18#.#8.218.133':27930
- '<LOCALNET>..0.42':27930
- '<LOCALNET>..51.118':27930
- '<LOCALNET>..0.43':27930
- '<LOCALNET>..51.119':27930
- '<LOCALNET>..0.44':27930
- '<LOCALNET>..51.120':27930
- '<LOCALNET>..0.45':27930
- '19#.#5.222.155':27930
- '<LOCALNET>..51.121':27930
- '<LOCALNET>..0.46':27930
- '<LOCALNET>..51.122':27930
- '<LOCALNET>..0.50':27930
- '<LOCALNET>..0.47':27930
- '<LOCALNET>..51.123':27930
- '<LOCALNET>..0.48':27930
- '<LOCALNET>..51.124':27930
- '<LOCALNET>..0.49':27930
- '19#.#51.12.63':27930
- '<LOCALNET>..51.125':27930
- '<LOCALNET>..0.54':27930
- '<LOCALNET>..51.126':27930
- '<LOCALNET>..0.51':27930
- '<LOCALNET>..51.127':27930
- '<LOCALNET>..0.52':27930
- '<LOCALNET>..51.128':27930
- '<LOCALNET>..0.53':27930
- '<LOCALNET>..51.129':27930
- '20#.71.0.93':27930
- '<LOCALNET>..0.58':27930
- '<LOCALNET>..51.130':27930
- '<LOCALNET>..0.55':27930
- '<LOCALNET>..51.131':27930
- '<LOCALNET>..0.56':27930
- '<LOCALNET>..51.132':27930
- '<LOCALNET>..0.57':27930
- '20#.#35.34.69':27930
- '<LOCALNET>..51.133':27930
- '<LOCALNET>..0.59':27930
- '<LOCALNET>..51.134':27930
- '<LOCALNET>..0.61':27930
- '<LOCALNET>..51.135':27930
- '<LOCALNET>..0.60':27930
- '<LOCALNET>..51.136':27930
- '<LOCALNET>..0.62':27930
- '21#.#48.16.76':27930
- '<LOCALNET>..51.137':27930
- '<LOCALNET>..0.63':27930
- '<LOCALNET>..0.64':27930
- '<LOCALNET>..51.138':27930
- '<LOCALNET>..0.65':27930
- '<LOCALNET>..51.139':27930
- '<LOCALNET>..0.66':27930
- '<LOCALNET>..51.140':27930
- '<LOCALNET>..0.67':27930
- '<LOCALNET>..51.141':27930
- '<LOCALNET>..0.69':27930
- '<LOCALNET>..51.142':27930
- '<LOCALNET>..0.68':27930
- '<LOCALNET>..51.143':27930
- '<LOCALNET>..0.72':27930
- '<LOCALNET>..51.144':27930
- '<LOCALNET>..0.70':27930
- '<LOCALNET>..51.145':27930
- '<LOCALNET>..0.71':27930
- '<LOCALNET>..51.146':27930
- '<LOCALNET>..0.73':27930
- '<LOCALNET>..51.147':27930
- '<LOCALNET>..0.74':27930
- '<LOCALNET>..51.148':27930
- '<LOCALNET>..0.75':27930
- '<LOCALNET>..51.149':27930
- '<LOCALNET>..0.79':27930
- '<LOCALNET>..51.150':27930
- '<LOCALNET>..0.76':27930
- '<LOCALNET>..51.151':27930
- '<LOCALNET>..0.77':27930
- '<LOCALNET>..51.152':27930
- '<LOCALNET>..0.78':27930
- '<LOCALNET>..51.153':27930
- '<LOCALNET>..0.82':27930
- '<LOCALNET>..51.154':27930
- '<LOCALNET>..0.80':27930
- '<LOCALNET>..51.155':27930
- '<LOCALNET>..0.81':27930
- '<LOCALNET>..51.156':27930
- '<LOCALNET>..0.86':27930
- '<LOCALNET>..51.157':27930
- '<LOCALNET>..0.83':27930
- '<LOCALNET>..51.158':27930
- '<LOCALNET>..0.84':27930
- '<LOCALNET>..0.85':27930
- '<LOCALNET>..51.159':27930
- '<LOCALNET>..0.87':27930
- '<LOCALNET>..51.160':27930
- '<LOCALNET>..0.90':27930
- '<LOCALNET>..51.161':27930
- '<LOCALNET>..0.88':27930
- '<LOCALNET>..51.162':27930
- '<LOCALNET>..0.89':27930
- '<LOCALNET>..51.163':27930
- '<LOCALNET>..0.91':27930
- '<LOCALNET>..51.164':27930
- '<LOCALNET>..0.92':27930
- '<LOCALNET>..51.165':27930
- '<LOCALNET>..0.94':27930
- '<LOCALNET>..51.166':27930
- '<LOCALNET>..0.93':27930
- '<LOCALNET>..51.167':27930
- '<LOCALNET>..0.98':27930
- '<LOCALNET>..51.168':27930
- '<LOCALNET>..0.95':27930
- '<LOCALNET>..51.169':27930
- '<LOCALNET>..0.96':27930
- '<LOCALNET>..51.170':27930
- '<LOCALNET>..0.97':27930
- '<LOCALNET>..51.171':27930
- '<LOCALNET>..0.101':27930
- '<LOCALNET>..51.172':27930
- '<LOCALNET>..0.99':27930
- '<LOCALNET>..51.173':27930
- '<LOCALNET>..0.100':27930
- '<LOCALNET>..51.174':27930
- '<LOCALNET>..0.102':27930
- '<LOCALNET>..51.175':27930
- '<LOCALNET>..0.103':27930
- '<LOCALNET>..51.176':27930
- '<LOCALNET>..0.104':27930
- '<LOCALNET>..51.177':27930
- '<LOCALNET>..0.105':27930
- '<LOCALNET>..51.178':27930
- '<LOCALNET>..0.109':27930
- '<LOCALNET>..51.179':27930
- '<LOCALNET>..0.106':27930
- '<LOCALNET>..51.180':27930
- '<LOCALNET>..0.107':27930
- '<LOCALNET>..0.108':27930
- '<LOCALNET>..51.181':27930
- '<LOCALNET>..0.110':27930
- '<LOCALNET>..51.182':27930
- '<LOCALNET>..0.113':27930
- '<LOCALNET>..51.183':27930
- '<LOCALNET>..0.111':27930
- '<LOCALNET>..51.184':27930
- '<LOCALNET>..0.112':27930
- '<LOCALNET>..51.185':27930
- '<LOCALNET>..0.114':27930
- '<LOCALNET>..51.186':27930
- '<LOCALNET>..0.115':27930
- '<LOCALNET>..51.187':27930
- '<LOCALNET>..0.116':27930
- '<LOCALNET>..51.188':27930
- '<LOCALNET>..0.117':27930
- '<LOCALNET>..51.189':27930
- '<LOCALNET>..0.118':27930
- '<LOCALNET>..51.190':27930
- '<LOCALNET>..0.120':27930
- '<LOCALNET>..51.191':27930
- '<LOCALNET>..0.119':27930
- '<LOCALNET>..51.192':27930
- '<LOCALNET>..0.124':27930
- '<LOCALNET>..51.193':27930
- '<LOCALNET>..0.121':27930
- '<LOCALNET>..51.194':27930
- '<LOCALNET>..0.122':27930
- '<LOCALNET>..51.195':27930
- '<LOCALNET>..0.123':27930
- '<LOCALNET>..51.196':27930
- '<LOCALNET>..0.127':27930
- '<LOCALNET>..51.197':27930
- '<LOCALNET>..0.125':27930
- '<LOCALNET>..51.198':27930
- '<LOCALNET>..0.126':27930
- '<LOCALNET>..51.199':27930
- '<LOCALNET>..0.128':27930
- '<LOCALNET>..51.200':27930
- '<LOCALNET>..0.129':27930
- '<LOCALNET>..51.201':27930
- '<LOCALNET>..0.130':27930
- '<LOCALNET>..51.202':27930
- '<LOCALNET>..0.131':27930
- '<LOCALNET>..51.203':27930
- '<LOCALNET>..0.135':27930
- '<LOCALNET>..0.132':27930
- '<LOCALNET>..51.204':27930
- '<LOCALNET>..0.133':27930
- '<LOCALNET>..51.205':27930
- '<LOCALNET>..0.134':27930
- '<LOCALNET>..51.206':27930
- '<LOCALNET>..0.138':27930
- '<LOCALNET>..51.207':27930
- '<LOCALNET>..0.136':27930
- '<LOCALNET>..51.208':27930
- '<LOCALNET>..0.137':27930
- '<LOCALNET>..51.209':27930
- '<LOCALNET>..0.139':27930
- '<LOCALNET>..51.210':27930
- '<LOCALNET>..0.140':27930
- '<LOCALNET>..51.211':27930
- '<LOCALNET>..0.141':27930
- '<LOCALNET>..51.212':27930
- '<LOCALNET>..0.145':27930
- '<LOCALNET>..51.213':27930
- '<LOCALNET>..0.142':27930
- '<LOCALNET>..51.214':27930
- '<LOCALNET>..0.143':27930
- '<LOCALNET>..51.215':27930
- '<LOCALNET>..0.144':27930
- '<LOCALNET>..51.216':27930
- '<LOCALNET>..0.149':27930
- '<LOCALNET>..51.217':27930
- '<LOCALNET>..0.146':27930
- '<LOCALNET>..51.218':27930
- '<LOCALNET>..0.147':27930
- '<LOCALNET>..51.219':27930
- '<LOCALNET>..0.148':27930
- '<LOCALNET>..51.220':27930
- '<LOCALNET>..0.153':27930
- '<LOCALNET>..51.221':27930
- '<LOCALNET>..0.150':27930
- '<LOCALNET>..51.222':27930
- '<LOCALNET>..0.151':27930
- '<LOCALNET>..51.223':27930
- '<LOCALNET>..0.152':27930
- '<LOCALNET>..51.224':27930
- '<LOCALNET>..0.154':27930
- '<LOCALNET>..51.225':27930
- '<LOCALNET>..0.155':27930
- '<LOCALNET>..0.156':27930
- '<LOCALNET>..51.226':27930
- '<LOCALNET>..0.157':27930
- '<LOCALNET>..51.227':27930
- '<LOCALNET>..0.160':27930
- '<LOCALNET>..51.228':27930
- '<LOCALNET>..0.158':27930
- '<LOCALNET>..51.229':27930
- '<LOCALNET>..0.159':27930
- '<LOCALNET>..51.230':27930
- '<LOCALNET>..0.161':27930
- '<LOCALNET>..51.231':27930
- '<LOCALNET>..0.165':27930
- '<LOCALNET>..51.232':27930
- '<LOCALNET>..0.166':27930
- '<LOCALNET>..51.233':27930
- '<LOCALNET>..0.162':27930
- '<LOCALNET>..51.234':27930
- '<LOCALNET>..0.163':27930
- '<LOCALNET>..51.235':27930
- '<LOCALNET>..0.164':27930
- '<LOCALNET>..51.236':27930
- '<LOCALNET>..0.170':27930
- '<LOCALNET>..51.237':27930
- '<LOCALNET>..0.167':27930
- '<LOCALNET>..51.238':27930
- '<LOCALNET>..0.168':27930
- '<LOCALNET>..51.239':27930
- '<LOCALNET>..0.169':27930
- '<LOCALNET>..51.240':27930
- '<LOCALNET>..0.174':27930
- '<LOCALNET>..51.241':27930
- '<LOCALNET>..0.175':27930
- '<LOCALNET>..51.242':27930
- '<LOCALNET>..0.171':27930
- '<LOCALNET>..51.243':27930
- '<LOCALNET>..0.172':27930
- '<LOCALNET>..51.244':27930
- '<LOCALNET>..0.173':27930
- '<LOCALNET>..51.245':27930
- '<LOCALNET>..0.179':27930
- '<LOCALNET>..51.246':27930
- '<LOCALNET>..0.176':27930
- '<LOCALNET>..0.177':27930
- '<LOCALNET>..51.247':27930
- '<LOCALNET>..0.178':27930
- '<LOCALNET>..51.248':27930
- '<LOCALNET>..0.180':27930
- '<LOCALNET>..51.249':27930
- '<LOCALNET>..0.183':27930
- '<LOCALNET>..51.250':27930
- '<LOCALNET>..0.181':27930
- '<LOCALNET>..51.251':27930
- '<LOCALNET>..0.182':27930
- '<LOCALNET>..51.252':27930
- '<LOCALNET>..0.187':27930
- '<LOCALNET>..51.253':27930
- '<LOCALNET>..0.184':27930
- '<LOCALNET>..51.254':27930
- '<LOCALNET>..0.185':27930
- '<LOCALNET>..0.186':27930
- '<LOCALNET>..0.191':27930
- '<LOCALNET>..0.188':27930
- '<LOCALNET>..0.189':27930
- '<LOCALNET>..0.190':27930
- '<LOCALNET>..0.192':27930
- '<LOCALNET>..0.194':27930
- '<LOCALNET>..0.193':27930
- '<LOCALNET>..0.195':27930
- '<LOCALNET>..0.198':27930
- '<LOCALNET>..0.196':27930
- '<LOCALNET>..0.197':27930
- '<LOCALNET>..0.202':27930
- '<LOCALNET>..0.199':27930
- '<LOCALNET>..0.200':27930
- '<LOCALNET>..0.201':27930
- '<LOCALNET>..0.205':27930
- '<LOCALNET>..0.203':27930
- '<SYSTEM32>\protection.exe' qhmblgkha