Техническая информация
- http://18#.#34.216.174/winstore.exe как %appdata%\winstore.exe
- %WINDIR%\explorer.exe
- %WINDIR%\syswow64\ipconfig.exe
- winstore.exe
- iexplore.exe
- firefox.exe
- Процесс firefox.exe, модуль nss3.dll
- Процесс iexplore.exe, модуль wininet.dll
- %TEMP%\abctfhghghghghВЈ.sct
- %PROGRAMDATA%\hrjytrj.cmd
- %APPDATA%\winstore.exe
- %APPDATA%\microsoft\windows\cookies\user@google[1].txt
- %APPDATA%\winstore.exe
- http://18#.#34.216.174/WinStore.exe
- DNS ASK do#########ocs.googleusercontent.com
- '%APPDATA%\winstore.exe'
- '%WINDIR%\syswow64\ipconfig.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%APPDATA%\WinStore.exe"