Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Tunneling Tablet Acquisition Hardware' = 'C:\czouvcxncatzkt\eqmtbfh.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\CNG Driver Coordinator Support] 'ImagePath' = 'C:\czouvcxncatzkt\eqmtbfh.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\CNG Driver Coordinator Support] 'Start' = '00000002'
- 'C:\czouvcxncatzkt\qttfmjiqvhs.exe' "c:\czouvcxncatzkt\eqmtbfh.exe"
- 'C:\czouvcxncatzkt\eqmtbfh.exe'
- 'C:\czouvcxncatzkt\dfc2gopgsjjazeai.exe'
- C:\czouvcxncatzkt\eqmtbfh.exe
- C:\czouvcxncatzkt\qttfmjiqvhs.exe
- C:\czouvcxncatzkt\ouxawoy8db
- %WINDIR%\czouvcxncatzkt\tzvgnp1h
- C:\czouvcxncatzkt\tzvgnp1h
- C:\czouvcxncatzkt\dfc2gopgsjjazeai.exe
- C:\czouvcxncatzkt\qttfmjiqvhs.exe
- C:\czouvcxncatzkt\eqmtbfh.exe
- C:\czouvcxncatzkt\dfc2gopgsjjazeai.exe
- %WINDIR%\czouvcxncatzkt\tzvgnp1h
- %WINDIR%\czouvcxncatzkt\tzvgnp1h
- '21#.#07.110.82':26314
- '19#.#6.240.249':21875
- '18#.#39.139.100':37599
- '17#.37.2.43':44303
- '12#.#60.112.138':27440
- '61.##6.2.217':25840
- '98.##.223.221':20922
- '21#.#7.168.28':52231
- '81.##7.50.99':52074
- '95.##8.241.220':49038
- '18#.#50.153.254':32097
- '18#.#42.145.105':26662
- ClassName: 'Shell_TrayWnd' WindowName: ''