Техническая информация
- %TEMP%\blocker.exe
- %TEMP%\cgsetup_en_xtxlmwcnge9fxqd6evyw.exe
- %TEMP%\ytmp\t2664.bat
- %TEMP%\ytmp\t2713.exe
- %TEMP%\ytmp\t2664.bat
- %TEMP%\ytmp\t2713.exe
- http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/02FAF3E291435468607857694DF5E45B68851868.crt
- http://oc##.#tartssl.com/sub/class2/code/ca/MEMwQTA%2FMD0wOzAJBgUrDgMCGgUABBQSOgrhRCSnWfKxoWTjWxhk8hga9AQU0E4PQJlsuEsZbzsouODjiAc0qrcCAhAV
- DNS ASK do######.cyberghostvpn.com
- DNS ASK oc##.#tartssl.com
- '%TEMP%\blocker.exe'
- '%TEMP%\cgsetup_en_xtxlmwcnge9fxqd6evyw.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\ytmp\t2664.bat" "%TEMP%\blocker.exe" "' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\ytmp\t2664.bat" "%TEMP%\blocker.exe" "
- '%WINDIR%\syswow64\attrib.exe' +h %TEMP%\ytmp