Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Alerts Biometric Health Removal Play BranchCache' = 'C:\umovwuewyiven\zcrldwp.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Config Color Function Connect Backup] 'ImagePath' = 'C:\umovwuewyiven\zcrldwp.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Config Color Function Connect Backup] 'Start' = '00000002'
- 'C:\umovwuewyiven\bdhbciorwtpg.exe' "c:\umovwuewyiven\zcrldwp.exe"
- 'C:\umovwuewyiven\zcrldwp.exe'
- 'C:\umovwuewyiven\lzewl54wonlocqfzqs2.exe'
- C:\umovwuewyiven\zcrldwp.exe
- C:\umovwuewyiven\bdhbciorwtpg.exe
- C:\umovwuewyiven\xcrcwhkt1o
- %WINDIR%\umovwuewyiven\ehnnvriat
- C:\umovwuewyiven\ehnnvriat
- C:\umovwuewyiven\lzewl54wonlocqfzqs2.exe
- C:\umovwuewyiven\bdhbciorwtpg.exe
- C:\umovwuewyiven\zcrldwp.exe
- C:\umovwuewyiven\lzewl54wonlocqfzqs2.exe
- %WINDIR%\umovwuewyiven\ehnnvriat
- %WINDIR%\umovwuewyiven\ehnnvriat
- '86.##.69.232':41590
- '12#.#60.123.173':36805
- '11#.#18.187.28':42065
- '5.##.147.5':26337
- '18#.#31.193.123':28122
- '88.#48.36.4':25752
- '21#.#65.0.136':35711
- '84.##8.128.25':27132
- '62.##.253.114':51156
- '86.##5.19.130':27743
- ClassName: 'Shell_TrayWnd' WindowName: ''