Техническая информация
- "%TEMP%\vrpbpls.exe" (загружен из сети Интернет)
- "%TEMP%\bhrrxxjn.exe" (загружен из сети Интернет)
- "%TEMP%\amew.exe" (загружен из сети Интернет)
- "%TEMP%\ahoelkmq.exe" (загружен из сети Интернет)
- "%TEMP%\senpj.exe" (загружен из сети Интернет)
- "%TEMP%\ilggau.exe" (загружен из сети Интернет)
- "%TEMP%\orpfqoh.exe" (загружен из сети Интернет)
- "%TEMP%\msigayw.exe" (загружен из сети Интернет)
- "%TEMP%\iwslwvy.exe" (загружен из сети Интернет)
- "%TEMP%\qarl.exe" (загружен из сети Интернет)
- "%TEMP%\750234914" (загружен из сети Интернет)
- "%TEMP%\ktftjn.exe" (загружен из сети Интернет)
- <SYSTEM32>\svchost.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\izgowq[1].php
- %TEMP%\vrpbpls.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\qhlkrzhf[1].php
- %TEMP%\amew.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\SL6TKFAX\tyfnhc[1].php
- %TEMP%\bhrrxxjn.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\ULU3YH2D\sjnlgn[1].php
- %TEMP%\ahoelkmq.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\SL6TKFAX\zptfzubjhp[1].php
- %TEMP%\ilggau.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\mmaucwe[1].php
- %TEMP%\senpj.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\SL6TKFAX\cptrlg[1].php
- %TEMP%\msigayw.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\hyfaitavt[1].php
- %TEMP%\orpfqoh.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\xavdxsz[1].php
- %TEMP%\iwslwvy.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\xbvqxsa[1].php
- %TEMP%\750234914
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\ULU3YH2D\kbwdyfeyta[1].php
- %TEMP%\qarl.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\iztbjhowu[1].php
- %TEMP%\ktftjn.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\ULU3YH2D\ultamgbih[1].php
- <SYSTEM32>\svchost.exe
- 'ad##rge.com':80
- ad##rge.com/timuo/qhlkrzhf.php?ad########
- ad##rge.com/timuo/izgowq.php?ad########
- ad##rge.com/timuo/tyfnhc.php?ad########
- ad##rge.com/timuo/zptfzubjhp.php?ad###################################################
- ad##rge.com/timuo/sjnlgn.php?ad########
- ad##rge.com/timuo/mmaucwe.php?ad########
- ad##rge.com/timuo/cptrlg.php?ad########
- ad##rge.com/timuo/hyfaitavt.php?ad########
- ad##rge.com/timuo/xbvqxsa.php?ad########
- ad##rge.com/timuo/xavdxsz.php?ad########
- ad##rge.com/timuo/kbwdyfeyta.php?ad########
- ad##rge.com/timuo/ultamgbih.php?ad########
- ad##rge.com/timuo/iztbjhowu.php?ad########
- DNS ASK ad##rge.com