Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Qery' = '"%APPDATA%\Uxki\qery.exe"'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DisableNotifications' = '00000001'
- '%APPDATA%\Uxki\qery.exe'
- <Служебный элемент>
- %TEMP%\tmp2b0fe6d6.bat
- <LS_APPDATA>\ohock.sof
- %APPDATA%\Uxki\qery.exe
- '18#.#48.91.99':16033
- '19#.#07.188.29':16517
- '84.##.222.81':10378
- '64.##0.155.194':19894
- '1.###.248.95':16869
- '41.##3.84.44':10074
- '19#.#51.139.137':25367
- '41.##.131.228':17933
- ClassName: 'Indicator' WindowName: ''