Техническая информация
- '%APPDATA%\csrss.exe' -prochide 2836
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe
- %TEMP%\alert.zip
- %HOMEPATH%\My Documents\KiIBtGxhpbhljhhTmkFvRQkEa.jpg
- %APPDATA%\csrss.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\blob[1]
- %APPDATA%\csrss.exe
- %TEMP%\alert.zip
- 'in###.mailjet.com':465
- 'ge.tt':80
- ge.tt/api/1/files/39FyKIg1/0/blob?do######
- DNS ASK in###.mailjet.com
- DNS ASK ge.tt