Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Detection Experience AuthIP Machine' = 'C:\pyivzfp\vpzdyuuswfuo.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\CNG Link-Layer DCOM Networking] 'ImagePath' = 'C:\pyivzfp\vpzdyuuswfuo.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\CNG Link-Layer DCOM Networking] 'Start' = '00000002'
- 'C:\pyivzfp\bnwobjfbk.exe' "c:\pyivzfp\vpzdyuuswfuo.exe"
- 'C:\pyivzfp\vpzdyuuswfuo.exe'
- 'C:\pyivzfp\iwp2d90rdvwpyctq8.exe'
- C:\pyivzfp\vpzdyuuswfuo.exe
- C:\pyivzfp\bnwobjfbk.exe
- C:\pyivzfp\asoqrt
- %WINDIR%\pyivzfp\ezirpqjiaxae
- C:\pyivzfp\ezirpqjiaxae
- C:\pyivzfp\iwp2d90rdvwpyctq8.exe
- C:\pyivzfp\bnwobjfbk.exe
- C:\pyivzfp\vpzdyuuswfuo.exe
- C:\pyivzfp\iwp2d90rdvwpyctq8.exe
- %WINDIR%\pyivzfp\ezirpqjiaxae
- %WINDIR%\pyivzfp\ezirpqjiaxae
- '22#.#1.110.45':48008
- '84.##8.128.25':27132
- '87.##.238.184':44724
- '77.##8.205.139':22969
- '41.##.10.183':48405
- '61.##6.2.217':25840
- '19#.#6.240.249':21875
- '95.##.58.101':23245
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''