Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'mn' = '%TEMP%\\dd.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'mn' = '%TEMP%\\da.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'startup' = '%TEMP%\\me.exe'
- '%TEMP%\pop.exe'
- %WINDIR%\microsoft.net\framework\v2.0.50727\regasm.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe
- %WINDIR%\microsoft.net\framework\v2.0.50727\regasm.exe
- %TEMP%\pop.exe
- %TEMP%\dd.exe
- %TEMP%\aut41dd.tmp
- %TEMP%\onfgxq.exe
- %TEMP%\aut4912.tmp
- %TEMP%\gmoxjh.exe
- %APPDATA%\windata\eoiikj.exe
- %TEMP%\da.exe
- %TEMP%\me.exe
- %TEMP%\aut41dd.tmp
- %TEMP%\aut4912.tmp
- 'co####temple.com':443
- DNS ASK co####temple.com
- '%TEMP%\onfgxq.exe'
- '%TEMP%\gmoxjh.exe'
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe'
- '%WINDIR%\microsoft.net\framework\v2.0.50727\regasm.exe'