Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Ordering Discovery Support' = 'C:\fmzjxrjm\szpipthgyejl.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Encrypting Launcher Services Upgrade] 'ImagePath' = 'C:\fmzjxrjm\szpipthgyejl.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Encrypting Launcher Services Upgrade] 'Start' = '00000002'
- 'C:\fmzjxrjm\fptvlchyraf.exe' "c:\fmzjxrjm\szpipthgyejl.exe"
- 'C:\fmzjxrjm\szpipthgyejl.exe'
- 'C:\fmzjxrjm\vzbwv359omuikalyr.exe'
- C:\fmzjxrjm\szpipthgyejl.exe
- C:\fmzjxrjm\fptvlchyraf.exe
- C:\fmzjxrjm\fsblje
- %WINDIR%\fmzjxrjm\bsapzqr
- C:\fmzjxrjm\bsapzqr
- C:\fmzjxrjm\vzbwv359omuikalyr.exe
- C:\fmzjxrjm\fptvlchyraf.exe
- C:\fmzjxrjm\szpipthgyejl.exe
- C:\fmzjxrjm\vzbwv359omuikalyr.exe
- %WINDIR%\fmzjxrjm\bsapzqr
- %WINDIR%\fmzjxrjm\bsapzqr
- 'pe####welcome.net':80
- 'ma####ewelcome.net':80
- 'ex####complete.net':80
- 'be####ecomplete.net':80
- http://pe####welcome.net/index.php
- http://ma####ewelcome.net/index.php
- http://ex####complete.net/index.php
- http://be####ecomplete.net/index.php
- DNS ASK ma####ewelcome.net
- DNS ASK pe####around.net
- DNS ASK pe####welcome.net
- DNS ASK ex####complete.net
- DNS ASK be####ecomplete.net
- ClassName: 'Shell_TrayWnd' WindowName: ''