Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Encryption AuthIP Hardware' = 'C:\hlmyumqzdue\yhwekttcxsq.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Receiver Store Policy Foundation] 'ImagePath' = 'C:\hlmyumqzdue\yhwekttcxsq.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Receiver Store Policy Foundation] 'Start' = '00000002'
- 'C:\hlmyumqzdue\oshxxil.exe' "c:\hlmyumqzdue\yhwekttcxsq.exe"
- 'C:\hlmyumqzdue\yhwekttcxsq.exe'
- 'C:\hlmyumqzdue\owdt2mc9vjiojzyvlwl.exe'
- C:\hlmyumqzdue\yhwekttcxsq.exe
- C:\hlmyumqzdue\oshxxil.exe
- C:\hlmyumqzdue\ij0uqgar5x
- %WINDIR%\hlmyumqzdue\gfdvhhfytlzh
- C:\hlmyumqzdue\gfdvhhfytlzh
- C:\hlmyumqzdue\owdt2mc9vjiojzyvlwl.exe
- C:\hlmyumqzdue\oshxxil.exe
- C:\hlmyumqzdue\yhwekttcxsq.exe
- C:\hlmyumqzdue\owdt2mc9vjiojzyvlwl.exe
- %WINDIR%\hlmyumqzdue\gfdvhhfytlzh
- %WINDIR%\hlmyumqzdue\gfdvhhfytlzh
- '11#.#6.137.96':49919
- '81.##7.50.99':52074
- '91.##.35.122':26126
- '15#.#82.245.137':33982
- '41.##.10.183':48405
- '86.#8.69.58':22437
- '17#.#50.138.208':20422
- '93.##7.67.155':25640
- '10#.#02.79.27':36272
- '18#.#22.43.28':46084
- '95.##.58.101':23245
- '79.##3.139.198':21201
- ClassName: 'Shell_TrayWnd' WindowName: ''