Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\bitbde0.tmp
- %WINDIR%\tasks\ping.job
- <SYSTEM32>\tasks\ping
- '%TEMP%\2895135.exe'
- %TEMP%\string.dll
- '<SYSTEM32>\mstsc.exe'
- <SYSTEM32>\mstsc.exe
- %WINDIR%\syswow64\mstsc.exe
- %WINDIR%\syswow64\cmd.exe
- %TEMP%\string.dll
- %TEMP%\1085423.dat
- %TEMP%\2895135.exe
- %TEMP%\bit2354.tmp
- %TEMP%\1e57965d.png
- %APPDATA%\adobe\bitb4e6.tmp
- %TEMP%\63834630.lnk
- %APPDATA%\adobe\bitb4e6.tmp
- %APPDATA%\microsoft\windows\start menu\programs\startup\bitbde0.tmp
- %TEMP%\bit2354.tmp
- %APPDATA%\adobe\bitb4e6.tmp в %APPDATA%\adobe\ping.exe
- http://oc##.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS%2BzcBkvzl4%3D
- DNS ASK pa###bin.com
- DNS ASK i.##gur.com
- DNS ASK di###diana.com
- DNS ASK oc##.thawte.com
- '%WINDIR%\syswow64\mstsc.exe'
- '%WINDIR%\syswow64\cmd.exe'