Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Connections Port IP Key Reporting Process' = 'C:\tjrrhqxlxgxotak\nllhcjzspy.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Class Extender Log Image Shell] 'ImagePath' = 'C:\tjrrhqxlxgxotak\nllhcjzspy.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Class Extender Log Image Shell] 'Start' = '00000002'
- 'C:\tjrrhqxlxgxotak\lhphcnxr.exe' "c:\tjrrhqxlxgxotak\nllhcjzspy.exe"
- 'C:\tjrrhqxlxgxotak\nllhcjzspy.exe'
- 'C:\tjrrhqxlxgxotak\atkz2oq7muoz0iqd.exe'
- C:\tjrrhqxlxgxotak\nllhcjzspy.exe
- C:\tjrrhqxlxgxotak\lhphcnxr.exe
- C:\tjrrhqxlxgxotak\lc1iov
- %WINDIR%\tjrrhqxlxgxotak\bvjdr9p
- C:\tjrrhqxlxgxotak\bvjdr9p
- C:\tjrrhqxlxgxotak\atkz2oq7muoz0iqd.exe
- C:\tjrrhqxlxgxotak\lhphcnxr.exe
- C:\tjrrhqxlxgxotak\nllhcjzspy.exe
- C:\tjrrhqxlxgxotak\atkz2oq7muoz0iqd.exe
- %WINDIR%\tjrrhqxlxgxotak\bvjdr9p
- %WINDIR%\tjrrhqxlxgxotak\bvjdr9p
- '98.##.223.221':20922
- '81.##4.87.112':37714
- '10#.#24.230.242':49777
- '18#.#39.139.100':37599
- '10#.#29.186.201':47507
- '86.##.69.232':41590
- '87.##.238.184':44724
- '19#.#6.240.249':21875
- '10#.#02.79.27':36272
- '79.##3.139.198':21201
- ClassName: 'Shell_TrayWnd' WindowName: ''