Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Auto-Discovery Name Extender Collector iSCSI' = 'C:\lxphxvi\pcbbimzmp.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\PC Engine Machine Plug Registry] 'Start' = '00000002'
- 'C:\lxphxvi\htazgmnrwfdq.exe' "c:\lxphxvi\pcbbimzmp.exe"
- 'C:\lxphxvi\pcbbimzmp.exe'
- 'C:\lxphxvi\oeofn5hi8ljeovfzxich.exe'
- C:\lxphxvi\pcbbimzmp.exe
- C:\lxphxvi\htazgmnrwfdq.exe
- C:\lxphxvi\iort5hp
- %WINDIR%\lxphxvi\ajpswavn
- C:\lxphxvi\ajpswavn
- C:\lxphxvi\oeofn5hi8ljeovfzxich.exe
- C:\lxphxvi\htazgmnrwfdq.exe
- C:\lxphxvi\pcbbimzmp.exe
- C:\lxphxvi\oeofn5hi8ljeovfzxich.exe
- %WINDIR%\lxphxvi\ajpswavn
- 'fo####father.net':80
- http://fo####father.net/index.php?me########
- DNS ASK fo###tapple.net
- DNS ASK in####seapple.net
- DNS ASK fo####father.net
- DNS ASK in####sefather.net
- ClassName: 'Shell_TrayWnd' WindowName: ''