Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\bitb32d.tmp
- %WINDIR%\tasks\dpcstart.job
- <SYSTEM32>\tasks\dpcstart
- '%TEMP%\5970633.exe'
- %TEMP%\countrycode.dll
- '<SYSTEM32>\lsm.exe'
- <SYSTEM32>\lsm.exe
- %WINDIR%\syswow64\mstsc.exe
- %WINDIR%\syswow64\cmd.exe
- %WINDIR%\syswow64\cmd.exe
- %TEMP%\countrycode.dll
- %TEMP%\1118361.dat
- %TEMP%\5970633.exe
- %TEMP%\bit7b9.tmp
- %TEMP%\a68138df.png
- %APPDATA%\icqm\bit9b5e.tmp
- %TEMP%\b74aa1d8.lnk
- %APPDATA%\icqm\bit9b5e.tmp
- %APPDATA%\microsoft\windows\start menu\programs\startup\bitb32d.tmp
- %TEMP%\bit7b9.tmp
- %APPDATA%\icqm\bit9b5e.tmp в %APPDATA%\icqm\dpcstart.exe
- 'sw##v.com':4545
- 'pa###bin.com':443
- 'i.##gur.com':443
- DNS ASK pa###bin.com
- DNS ASK i.##gur.com
- DNS ASK sw##v.com
- '%WINDIR%\syswow64\mstsc.exe'
- '%WINDIR%\syswow64\cmd.exe'