Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Connection Driver PC Information' = 'C:\idbivprherqoma\fiqsrwplyaws.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Resource Keying Portable DNS] 'ImagePath' = 'C:\idbivprherqoma\fiqsrwplyaws.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Resource Keying Portable DNS] 'Start' = '00000002'
- 'C:\idbivprherqoma\flugmkfmlen.exe' "c:\idbivprherqoma\fiqsrwplyaws.exe"
- 'C:\idbivprherqoma\fiqsrwplyaws.exe'
- 'C:\idbivprherqoma\ebpt3jlrivmwcjhxnkb.exe'
- C:\idbivprherqoma\fiqsrwplyaws.exe
- C:\idbivprherqoma\flugmkfmlen.exe
- C:\idbivprherqoma\t4sjrhwdsx
- %WINDIR%\idbivprherqoma\hzfwm06pq
- C:\idbivprherqoma\hzfwm06pq
- C:\idbivprherqoma\ebpt3jlrivmwcjhxnkb.exe
- C:\idbivprherqoma\flugmkfmlen.exe
- C:\idbivprherqoma\fiqsrwplyaws.exe
- C:\idbivprherqoma\ebpt3jlrivmwcjhxnkb.exe
- %WINDIR%\idbivprherqoma\hzfwm06pq
- %WINDIR%\idbivprherqoma\hzfwm06pq
- '88.##.203.114':40413
- '10#.#25.112.152':47507
- '88.#48.36.4':25752
- '20#.#71.22.221':32994
- '92.##7.45.207':21921
- '77.##7.13.68':30018
- '18#.#55.161.27':20052
- '20#.#70.207.211':37727
- ClassName: 'Shell_TrayWnd' WindowName: ''