Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Volume CardSpace SPP Cryptographic Installer' = 'C:\csvaepzbice\wtnfxquem.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Key Connectivity Gateway Distributed TPM] 'ImagePath' = 'C:\csvaepzbice\wtnfxquem.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Key Connectivity Gateway Distributed TPM] 'Start' = '00000002'
- 'C:\csvaepzbice\riijtikqf.exe' "c:\csvaepzbice\wtnfxquem.exe"
- 'C:\csvaepzbice\wtnfxquem.exe'
- 'C:\csvaepzbice\rx36vuqikr2tylodlyw.exe'
- C:\csvaepzbice\wtnfxquem.exe
- C:\csvaepzbice\riijtikqf.exe
- C:\csvaepzbice\ihvikmeyet
- %WINDIR%\csvaepzbice\rxccwvp
- C:\csvaepzbice\rxccwvp
- C:\csvaepzbice\rx36vuqikr2tylodlyw.exe
- C:\csvaepzbice\riijtikqf.exe
- C:\csvaepzbice\wtnfxquem.exe
- C:\csvaepzbice\rxccwvp
- C:\csvaepzbice\rx36vuqikr2tylodlyw.exe
- %WINDIR%\csvaepzbice\rxccwvp
- C:\csvaepzbice\rxccwvp
- %WINDIR%\csvaepzbice\rxccwvp
- '62.##1.108.194':20068
- '18#.#42.145.105':26662
- '12#.#60.123.173':36805
- '18#.#0.243.3':25741
- '86.#8.69.58':22437
- '19#.#47.86.10':25432
- '41.##.10.183':48405
- '22#.#1.110.45':48008
- '77.##7.13.68':30018
- '12#.#60.112.138':27440
- ClassName: 'Shell_TrayWnd' WindowName: ''