Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Encrypting Logs Drive Window Player' = 'C:\ykxicdhthzwrcg\cuoqjtuywgqm.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Awareness Interactive Controls] 'ImagePath' = 'C:\ykxicdhthzwrcg\cuoqjtuywgqm.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Awareness Interactive Controls] 'Start' = '00000002'
- 'C:\ykxicdhthzwrcg\yimpuwjw.exe' "c:\ykxicdhthzwrcg\cuoqjtuywgqm.exe"
- 'C:\ykxicdhthzwrcg\cuoqjtuywgqm.exe'
- 'C:\ykxicdhthzwrcg\git2ttdooo1aun8ueh.exe'
- C:\ykxicdhthzwrcg\cuoqjtuywgqm.exe
- C:\ykxicdhthzwrcg\yimpuwjw.exe
- C:\ykxicdhthzwrcg\wbj0kz1pea
- %WINDIR%\ykxicdhthzwrcg\joc4j0avgd
- C:\ykxicdhthzwrcg\joc4j0avgd
- C:\ykxicdhthzwrcg\git2ttdooo1aun8ueh.exe
- C:\ykxicdhthzwrcg\yimpuwjw.exe
- C:\ykxicdhthzwrcg\cuoqjtuywgqm.exe
- C:\ykxicdhthzwrcg\git2ttdooo1aun8ueh.exe
- %WINDIR%\ykxicdhthzwrcg\joc4j0avgd
- %WINDIR%\ykxicdhthzwrcg\joc4j0avgd
- '22#.#1.110.45':48008
- '12#.#60.112.138':27440
- '81.##4.87.112':37714
- '2.##.19.50':35833
- '77.##8.205.139':22969
- '20#.#23.152.97':27682
- '18#.#5.131.224':26337
- '10#.#46.77.146':33927
- ClassName: 'Shell_TrayWnd' WindowName: ''