Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Internet Human NGEN Class' = 'C:\glsmtbhwpix\vfsvebd.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Accounts Print Video Agent Net.Tcp] 'ImagePath' = 'C:\glsmtbhwpix\vfsvebd.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Accounts Print Video Agent Net.Tcp] 'Start' = '00000002'
- 'C:\glsmtbhwpix\vkkqchtpr.exe' "c:\glsmtbhwpix\vfsvebd.exe"
- 'C:\glsmtbhwpix\vfsvebd.exe'
- 'C:\glsmtbhwpix\dhjdd2h1qsiyubdnenjtl.exe'
- C:\glsmtbhwpix\vfsvebd.exe
- C:\glsmtbhwpix\vkkqchtpr.exe
- C:\glsmtbhwpix\fmzsp7
- %WINDIR%\glsmtbhwpix\pyssaiev
- C:\glsmtbhwpix\pyssaiev
- C:\glsmtbhwpix\dhjdd2h1qsiyubdnenjtl.exe
- C:\glsmtbhwpix\vkkqchtpr.exe
- C:\glsmtbhwpix\vfsvebd.exe
- C:\glsmtbhwpix\dhjdd2h1qsiyubdnenjtl.exe
- %WINDIR%\glsmtbhwpix\pyssaiev
- %WINDIR%\glsmtbhwpix\pyssaiev
- '24.##9.216.168':33794
- '84.##8.128.25':27132
- '41.##.10.183':48405
- '82.##7.164.91':40801
- '18#.#42.145.105':26662
- '87.##.238.184':44724
- '18#.#23.70.113':37727
- '17#.#50.138.208':20422
- '17#.37.2.43':44303
- ClassName: 'Shell_TrayWnd' WindowName: ''