Техническая информация
- %WINDIR%\Tasks\services update.job
- 'C:\Documents and Settings\NetworkService\Application Data\winapp\a440cd27.exe'
- '%APPDATA%\winapp\a551de38.exe'
- 'C:\Documents and Settings\NetworkService\Application Data\winapp\a440cd27.exe'
- '%APPDATA%\winapp\a551de38.exe'
- a440cd27.exe
- C:\Documents and Settings\NetworkService\Application Data\winapp\a440cd27.exe
- %WINDIR%\Temp\~DFEE01.tmp
- %WINDIR%\Temp\~DFED1D.tmp
- C:\Documents and Settings\NetworkService\Application Data\winapp\client_id
- %WINDIR%\Temp\~DF405.tmp
- %WINDIR%\Temp\~DF321.tmp
- %APPDATA%\winapp\a551de38.exe
- %TEMP%\~DF618E.tmp
- %TEMP%\~DF6057.tmp
- %APPDATA%\winapp\client_id
- %TEMP%\~DF7DF1.tmp
- %TEMP%\~DF7CDF.tmp
- %WINDIR%\Temp\~DFED1D.tmp
- %WINDIR%\Temp\~DFEE01.tmp
- %WINDIR%\Temp\~DF321.tmp
- %WINDIR%\Temp\~DF405.tmp
- %TEMP%\~DF6057.tmp
- %TEMP%\~DF618E.tmp
- %TEMP%\~DF7CDF.tmp
- %TEMP%\~DF7DF1.tmp
- 'my####rnalip.com':80
- http://my####rnalip.com/raw
- DNS ASK my####rnalip.com