Техническая информация
- %WINDIR%\Tasks\{7FAE7CAD-42CD-2F75-2138-24203558283D}.job
- '%APPDATA%\Mozilla\Extensions\qoaeifo.exe'
- <SYSTEM32>\cmd.exe
- <SYSTEM32>\cscript.exe
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\ctfmon.exe
- [<HKCU>\Software\Microsoft\messengerservice]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\reporta[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\reporta[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\reporta[1].htm
- %APPDATA%\Mozilla\Extensions\qoaeifo.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\reporta[1].htm
- %WINDIR%\Tasks\{7FAE7CAD-42CD-2F75-2138-24203558283D}.job
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\reporta[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\reporta[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\reporta[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\reporta[1].htm
- 'sy#.###ktravestiler.org':80
- 'lo##.#rqadas.net':80
- 'vo##.#rkadasci.com':80
- sy#.###ktravestiler.org/reporta.php
- lo##.#rqadas.net/reporta.php
- vo##.#rkadasci.com/reporta.php
- DNS ASK sy#.###ktravestiler.org
- DNS ASK lo##.#rqadas.net
- DNS ASK vo##.#rkadasci.com