Техническая информация
- %WINDIR%\Downloaded Program Files\svchost.exe 192.168.19.3 http://b.##d6.com/ww.exe 192.168.19.4 http://b.##d6.com/ww.exe 192.168.19.1 http://b.##d6.com/ww.exe 192.168.19.2 http://b.##d6.com/ww.exe
- %WINDIR%\Fonts\cmdd
- <SYSTEM32>\364safe.exe
- %WINDIR%\Fonts\svchost.exe
- <SYSTEM32>\cmd.exe /c c:\DEL.bat
- <SYSTEM32>\svchost.exe
- <DRIVERS>\Atieccx.sys
- \Device\LanmanRedirector\192.168.19.2\pipe\browser
- \Device\LanmanRedirector\192.168.19.3\pipe\browser
- \Device\LanmanRedirector\192.168.19.4\pipe\browser
- C:\DEL.bat
- %WINDIR%\Fonts\cmdd
- <SYSTEM32>\364safe.exe
- <SYSTEM32>\mssvfcsg.dll
- %WINDIR%\Fonts\svchost.exe
- \Device\LanmanRedirector\192.168.19.1\pipe\browser
- %WINDIR%\Downloaded Program Files\svchost.exe
- %WINDIR%\Fonts\cmdd
- '<IP-адрес в локальной сети>':139
- '<IP-адрес в локальной сети>':445