Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Studio Networking Drive Volume' = 'C:\wnebnxblvvv\apdoxsa.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Modules Isolation Session Studio Office] 'ImagePath' = 'C:\wnebnxblvvv\apdoxsa.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Modules Isolation Session Studio Office] 'Start' = '00000002'
- 'C:\wnebnxblvvv\imutunwfl.exe' "c:\wnebnxblvvv\apdoxsa.exe"
- 'C:\wnebnxblvvv\apdoxsa.exe'
- 'C:\wnebnxblvvv\attzs3133lllhqdxaoauw.exe'
- C:\wnebnxblvvv\apdoxsa.exe
- C:\wnebnxblvvv\imutunwfl.exe
- C:\wnebnxblvvv\ytghmmv
- %WINDIR%\wnebnxblvvv\fqyfm8cewf7
- C:\wnebnxblvvv\fqyfm8cewf7
- C:\wnebnxblvvv\attzs3133lllhqdxaoauw.exe
- C:\wnebnxblvvv\imutunwfl.exe
- C:\wnebnxblvvv\apdoxsa.exe
- C:\wnebnxblvvv\attzs3133lllhqdxaoauw.exe
- %WINDIR%\wnebnxblvvv\fqyfm8cewf7
- %WINDIR%\wnebnxblvvv\fqyfm8cewf7
- '77.##7.13.68':30018
- '15#.#82.245.137':33982
- '5.##.19.242':27426
- '73.##.228.84':36884
- '19#.#6.240.249':21875
- '70.##2.38.96':41500
- '62.##1.108.194':20068
- '82.##7.164.91':40801
- '81.##7.50.99':52074
- '84.##8.128.25':27132
- '10#.#4.136.243':42581
- '18#.#38.249.34':37331
- ClassName: 'Shell_TrayWnd' WindowName: ''