Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Diagnostic Virtual Transaction Configuration' = 'C:\akznvkg\emloqiecxz.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Policy Bus Multimedia WebClient Gateway] 'ImagePath' = 'C:\akznvkg\emloqiecxz.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Policy Bus Multimedia WebClient Gateway] 'Start' = '00000002'
- 'C:\akznvkg\bhbofhesmpl.exe' "c:\akznvkg\emloqiecxz.exe"
- 'C:\akznvkg\emloqiecxz.exe'
- 'C:\akznvkg\w435pbrwg7p3fgrt.exe'
- C:\akznvkg\emloqiecxz.exe
- C:\akznvkg\bhbofhesmpl.exe
- C:\akznvkg\in5uucuhxxc
- %WINDIR%\akznvkg\dy0wxy
- C:\akznvkg\dy0wxy
- C:\akznvkg\w435pbrwg7p3fgrt.exe
- C:\akznvkg\bhbofhesmpl.exe
- C:\akznvkg\emloqiecxz.exe
- C:\akznvkg\w435pbrwg7p3fgrt.exe
- %WINDIR%\akznvkg\dy0wxy
- %WINDIR%\akznvkg\dy0wxy
- '21#.#07.110.82':26314
- '18#.#42.145.105':26662
- '10#.#4.136.243':42581
- '11#.#6.137.96':49919
- '86.##5.19.130':27743
- '20#.#7.225.58':33073
- '5.##.147.5':26337
- '93.##7.67.155':25640
- '77.##8.205.139':22969
- '78.##5.171.93':23699
- ClassName: 'Shell_TrayWnd' WindowName: ''