Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Volume Gateway Disk Management' = 'C:\ufaumzpaj\ojszwzpmbal.exe'
- 'C:\ufaumzpaj\gfizptbjtlo.exe' "c:\ufaumzpaj\ojszwzpmbal.exe"
- 'C:\ufaumzpaj\ojszwzpmbal.exe'
- 'C:\ufaumzpaj\h62n4wydjcjtmwhwngh.exe'
- C:\ufaumzpaj\ojszwzpmbal.exe
- C:\ufaumzpaj\gfizptbjtlo.exe
- C:\ufaumzpaj\wbcbcaa1v
- %WINDIR%\ufaumzpaj\wrcsrvlqjgdc
- C:\ufaumzpaj\wrcsrvlqjgdc
- C:\ufaumzpaj\h62n4wydjcjtmwhwngh.exe
- C:\ufaumzpaj\gfizptbjtlo.exe
- C:\ufaumzpaj\ojszwzpmbal.exe
- C:\ufaumzpaj\h62n4wydjcjtmwhwngh.exe
- %WINDIR%\ufaumzpaj\wrcsrvlqjgdc
- 'qu####osition.net':80
- 'se####position.net':80
- 'qu###number.net':80
- 'se####number.net':80
- 'qu###strike.net':80
- 'se####partial.net':80
- 'ag####tattempt.net':80
- 'se####strike.net':80
- 'qu####artial.net':80
- 'br###number.net':80
- 'fl####osition.net':80
- 'ga####partial.net':80
- 'fl###number.net':80
- 'br####osition.net':80
- 'fl####artial.net':80
- 'br####artial.net':80
- 'fl###strike.net':80
- 'br###strike.net':80
- 'do####ttempt.net':80
- 'de####neighbor.net':80
- 'ni###spread.net':80
- 'de####square.net':80
- 'ni####eighbor.net':80
- 'de####spread.net':80
- 'la###square.net':80
- 'ca####nsquare.net':80
- 'la####ttempt.net':80
- 'ca####nattempt.net':80
- 'ag####tneighbor.net':80
- 'do####eighbor.net':80
- 'ag####tsquare.net':80
- 'do###square.net':80
- 'ag####tspread.net':80
- 'de####attempt.net':80
- 'ni###square.net':80
- 'do###spread.net':80
- 'ni####ttempt.net':80
- 'ca####nstrike.net':80
- 'la####artial.net':80
- 'ca####nposition.net':80
- 'la###strike.net':80
- 'ca####npartial.net':80
- 're####position.net':80
- 'el#####cposition.net':80
- 're####number.net':80
- 'el####icnumber.net':80
- 'ni###strike.net':80
- 'de####strike.net':80
- 'ni####osition.net':80
- 'de####position.net':80
- 'ni####artial.net':80
- 'ca####nnumber.net':80
- 'la####osition.net':80
- 'de####partial.net':80
- 'la###number.net':80
- 're####strike.net':80
- 'be####number.net':80
- 'ga####number.net':80
- 'st####partial.net':80
- 'tr####artial.net':80
- 'be####position.net':80
- 'ga####strike.net':80
- 'be####partial.net':80
- 'ga####position.net':80
- 'be####strike.net':80
- 'el####icpartial.net':80
- 'st####number.net':80
- 'el####icstrike.net':80
- 're####partial.net':80
- 'tr###number.net':80
- 'st####strike.net':80
- 'tr###strike.net':80
- 'st####position.net':80
- 'tr####osition.net':80
- http://qu####osition.net/index.php?me########
- http://se####position.net/index.php?me########
- http://qu###number.net/index.php?me########
- http://se####number.net/index.php?me########
- http://qu###strike.net/index.php?me########
- http://se####partial.net/index.php?me########
- http://ag####tattempt.net/index.php?me########
- http://se####strike.net/index.php?me########
- http://qu####artial.net/index.php?me########
- http://br###number.net/index.php?me########
- http://fl####osition.net/index.php?me########
- http://ga####partial.net/index.php?me########
- http://fl###number.net/index.php?me########
- http://br####osition.net/index.php?me########
- http://fl####artial.net/index.php?me########
- http://br####artial.net/index.php?me########
- http://fl###strike.net/index.php?me########
- http://br###strike.net/index.php?me########
- http://do####ttempt.net/index.php?me########
- http://de####neighbor.net/index.php?me########
- http://ni###spread.net/index.php?me########
- http://de####square.net/index.php?me########
- http://ni####eighbor.net/index.php?me########
- http://de####spread.net/index.php?me########
- http://la###square.net/index.php?me########
- http://ca####nsquare.net/index.php?me########
- http://la####ttempt.net/index.php?me########
- http://ca####nattempt.net/index.php?me########
- http://ag####tneighbor.net/index.php?me########
- http://do####eighbor.net/index.php?me########
- http://ag####tsquare.net/index.php?me########
- http://do###square.net/index.php?me########
- http://ag####tspread.net/index.php?me########
- http://de####attempt.net/index.php?me########
- http://ni###square.net/index.php?me########
- http://do###spread.net/index.php?me########
- http://ni####ttempt.net/index.php?me########
- http://ca####nstrike.net/index.php?me########
- http://la####artial.net/index.php?me########
- http://ca####nposition.net/index.php?me########
- http://la###strike.net/index.php?me########
- http://ca####npartial.net/index.php?me########
- http://re####position.net/index.php?me########
- http://el#####cposition.net/index.php?me########
- http://re####number.net/index.php?me########
- http://el####icnumber.net/index.php?me########
- http://ni###strike.net/index.php?me########
- http://de####strike.net/index.php?me########
- http://ni####osition.net/index.php?me########
- http://de####position.net/index.php?me########
- http://ni####artial.net/index.php?me########
- http://ca####nnumber.net/index.php?me########
- http://la####osition.net/index.php?me########
- http://de####partial.net/index.php?me########
- http://la###number.net/index.php?me########
- http://re####strike.net/index.php?me########
- http://be####number.net/index.php?me########
- http://ga####number.net/index.php?me########
- http://st####partial.net/index.php?me########
- http://tr####artial.net/index.php?me########
- http://be####position.net/index.php?me########
- http://ga####strike.net/index.php?me########
- http://be####partial.net/index.php?me########
- http://ga####position.net/index.php?me########
- http://be####strike.net/index.php?me########
- http://el####icpartial.net/index.php?me########
- http://st####number.net/index.php?me########
- http://el####icstrike.net/index.php?me########
- http://re####partial.net/index.php?me########
- http://tr###number.net/index.php?me########
- http://st####strike.net/index.php?me########
- http://tr###strike.net/index.php?me########
- http://st####position.net/index.php?me########
- http://tr####osition.net/index.php?me########
- DNS ASK se####position.net
- DNS ASK qu###strike.net
- DNS ASK se####number.net
- DNS ASK qu####osition.net
- DNS ASK se####strike.net
- DNS ASK ag####tattempt.net
- DNS ASK do####ttempt.net
- DNS ASK qu####artial.net
- DNS ASK se####partial.net
- DNS ASK fl####osition.net
- DNS ASK br####osition.net
- DNS ASK fl###number.net
- DNS ASK br###number.net
- DNS ASK fl###strike.net
- DNS ASK br####artial.net
- DNS ASK qu###number.net
- DNS ASK br###strike.net
- DNS ASK fl####artial.net
- DNS ASK ag####tsquare.net
- DNS ASK ni###spread.net
- DNS ASK de####spread.net
- DNS ASK ni####eighbor.net
- DNS ASK de####neighbor.net
- DNS ASK la####ttempt.net
- DNS ASK ca####nsquare.net
- DNS ASK la####eighbor.net
- DNS ASK ca####nattempt.net
- DNS ASK la###square.net
- DNS ASK do####eighbor.net
- DNS ASK ag####tspread.net
- DNS ASK do###square.net
- DNS ASK ag####tneighbor.net
- DNS ASK do###spread.net
- DNS ASK ni###square.net
- DNS ASK de####square.net
- DNS ASK ni####ttempt.net
- DNS ASK de####attempt.net
- DNS ASK ga####partial.net
- DNS ASK ca####nstrike.net
- DNS ASK la####artial.net
- DNS ASK ca####nposition.net
- DNS ASK la###strike.net
- DNS ASK ca####npartial.net
- DNS ASK re####position.net
- DNS ASK el#####cposition.net
- DNS ASK re####number.net
- DNS ASK el####icnumber.net
- DNS ASK ni###strike.net
- DNS ASK de####strike.net
- DNS ASK ni####osition.net
- DNS ASK de####position.net
- DNS ASK ni####artial.net
- DNS ASK ca####nnumber.net
- DNS ASK la####osition.net
- DNS ASK de####partial.net
- DNS ASK la###number.net
- DNS ASK re####strike.net
- DNS ASK be####number.net
- DNS ASK ga####number.net
- DNS ASK st####partial.net
- DNS ASK tr####artial.net
- DNS ASK be####position.net
- DNS ASK ga####strike.net
- DNS ASK be####partial.net
- DNS ASK ga####position.net
- DNS ASK be####strike.net
- DNS ASK el####icpartial.net
- DNS ASK st####number.net
- DNS ASK el####icstrike.net
- DNS ASK re####partial.net
- DNS ASK tr###number.net
- DNS ASK st####strike.net
- DNS ASK tr###strike.net
- DNS ASK st####position.net
- DNS ASK tr####osition.net
- ClassName: 'Shell_TrayWnd' WindowName: ''