Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '{1D476073-5E7F-AD41-B897-60D4A63F43C6}' = '"%APPDATA%\Ohij\nuvyah.exe"'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DisableNotifications' = '00000001'
- '%APPDATA%\Ohij\nuvyah.exe'
- <SYSTEM32>\cscript.exe
- %TEMP%\tmp4169d821.bat
- <LS_APPDATA>\ewfyz.pok
- %APPDATA%\Ohij\nuvyah.exe
- 'vs########qjnknbacabyjvpzheg.com':80
- 'mv#########sxolbqcaqkbobkfgetkbm.biz':80
- 'em#######qqwykjytoscnjgudzt.org':80
- '74.##5.232.51':80
- 'www.bing.com':80
- 'xf######nohtdipibsksk.ru':80
- http://vs########qjnknbacabyjvpzheg.com/
- http://mv#########sxolbqcaqkbobkfgetkbm.biz/
- http://em#######qqwykjytoscnjgudzt.org/
- http://www.google.com/ via 74.##5.232.51
- http://www.bing.com/
- http://xf######nohtdipibsksk.ru/
- DNS ASK xf######nohtdipibsksk.ru
- DNS ASK www.bing.com
- DNS ASK www.google.com
- DNS ASK vs########qjnknbacabyjvpzheg.com
- DNS ASK em#######qqwykjytoscnjgudzt.org
- DNS ASK mv#########sxolbqcaqkbobkfgetkbm.biz
- '18#.#9.41.30':18356
- '99.##0.165.132':25139
- '11#.#41.211.236':26092
- '99.##.188.39':17053
- '31.##2.29.137':28121
- '71.##6.48.91':22174
- '19#.#4.127.98':25549
- '12#.#64.109.238':12333
- '62.##3.27.242':10081
- '99.#6.3.38':15247
- '75.#.222.103':11577
- ClassName: 'Indicator' WindowName: ''