Техническая информация
- '%TEMP%\Tjgyjs.exe'
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- %TEMP%\Tjgyjs.exe
- %TEMP%\tm_EFC7e.txt
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- <SYSTEM32>\PerfStringBackup.TMP
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\page_241[1].pdf
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\page_241[1].pdf
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\page_241[1].pdf
- 'co#####fthemonth.biz':80
- 'mo##h-x.com':80
- '20#.#53.35.133':12012
- co#####fthemonth.biz/mandoc/page_241.pdf
- mo##h-x.com/mandoc/page_241.pdf
- DNS ASK co#####fthemonth.biz
- DNS ASK mo##h-x.com