Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Files Image Function Counter' = 'C:\cstvihpnrhso\mdgvcuonyjvy.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Portable Font Authentication] 'ImagePath' = 'C:\cstvihpnrhso\mdgvcuonyjvy.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Portable Font Authentication] 'Start' = '00000002'
- 'C:\cstvihpnrhso\bhawvna.exe' "c:\cstvihpnrhso\mdgvcuonyjvy.exe"
- 'C:\cstvihpnrhso\mdgvcuonyjvy.exe'
- 'C:\cstvihpnrhso\pwwen31g3jdraeedxhr.exe'
- C:\cstvihpnrhso\mdgvcuonyjvy.exe
- C:\cstvihpnrhso\bhawvna.exe
- C:\cstvihpnrhso\tcuxod4
- %WINDIR%\cstvihpnrhso\a0ihak
- C:\cstvihpnrhso\a0ihak
- C:\cstvihpnrhso\pwwen31g3jdraeedxhr.exe
- C:\cstvihpnrhso\bhawvna.exe
- C:\cstvihpnrhso\mdgvcuonyjvy.exe
- C:\cstvihpnrhso\pwwen31g3jdraeedxhr.exe
- %WINDIR%\cstvihpnrhso\a0ihak
- %WINDIR%\cstvihpnrhso\a0ihak
- '61.##6.2.217':25840
- '31.##7.83.237':44843
- '70.##2.38.96':41500
- '18#.#22.43.28':46084
- '5.##.147.5':26337
- '93.##7.67.155':25640
- '10#.#46.77.146':33927
- '20#.#95.172.22':41884
- '88.#48.36.4':25752
- '86.##.69.232':41590
- '15#.#82.245.137':33982
- '24.##9.216.168':33794
- '18#.#42.145.105':26662
- ClassName: 'Shell_TrayWnd' WindowName: ''