Техническая информация
- '<SYSTEM32>\taskkill.exe' /F /IM cmd.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\1J8L4m3C.bat
- '<SYSTEM32>\cmd.exe' /c %TEMP%\0N2y7U.bat
- '<SYSTEM32>\taskkill.exe' /f /t /im av*
- <SYSTEM32>\cmd.exe
- AVPCC.EXE
- AVP32.EXE
- AVSYNMGR.EXE
- AVPM.EXE
- AVP.EXE
- AVGCC32.EXE
- avgcc.exe
- AVP.COM
- AVGCTRL.EXE
- %PROGRAM_FILES%\3i7k2m6T6w\7H5H0W.7S2U1i
- %PROGRAM_FILES%\3i7k2m6T6w\0E8o4E.8C3Y7V
- %TEMP%\1J8L4m3C.bat
- %TEMP%\0N2y7U.bat
- %PROGRAM_FILES%\3i7k2m6T6w\1N8h3X.3C1I6T
- %PROGRAM_FILES%\3i7k2m6T6w\5c7q6k.2j2w5R
- %PROGRAM_FILES%\3i7k2m6T6w\7H5H0W.7S2U1i
- %PROGRAM_FILES%\3i7k2m6T6w\0E8o4E.8C3Y7V
- %PROGRAM_FILES%\3i7k2m6T6w\1N8h3X.3C1I6T
- %PROGRAM_FILES%\3i7k2m6T6w\5c7q6k.2j2w5R
- 'cp#######.publiccloud.com.br':80
- cp#######.publiccloud.com.br/150813/pe40/lucia30.pdf
- cp#######.publiccloud.com.br/150813/pe40/lucia40.pdf
- cp#######.publiccloud.com.br/150813/pe40/lucia10.pdf
- cp#######.publiccloud.com.br/150813/pe40/lucia20.pdf
- DNS ASK cp#######.publiccloud.com.br
- ClassName: 'MS_WINHELP' WindowName: '(null)'
- ClassName: '(null)' WindowName: '(null)'