Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\bit3998.tmp
- %WINDIR%\tasks\diskpart.job
- <SYSTEM32>\tasks\diskpart
- '%TEMP%\5267403.exe'
- %TEMP%\nl2br.dll
- '%WINDIR%\explorer.exe'
- %WINDIR%\explorer.exe
- %WINDIR%\syswow64\mstsc.exe
- %WINDIR%\syswow64\cmd.exe
- %TEMP%\nl2br.dll
- %TEMP%\1097627.dat
- %TEMP%\5267403.exe
- %TEMP%\bit8d2a.tmp
- %TEMP%\575f89c5.png
- %APPDATA%\icq-profile\update\splash_banner\bit1e9d.tmp
- %TEMP%\45640e52.lnk
- %APPDATA%\icq-profile\update\splash_banner\bit1e9d.tmp
- %APPDATA%\microsoft\windows\start menu\programs\startup\bit3998.tmp
- %TEMP%\bit8d2a.tmp
- %APPDATA%\icq-profile\update\splash_banner\bit1e9d.tmp в %APPDATA%\icq-profile\update\splash_banner\diskpart.exe
- 'xe##es.com':20200
- http://oc##.#tartssl.com/sub/class2/code/ca/MEMwQTA%2FMD0wOzAJBgUrDgMCGgUABBQSOgrhRCSnWfKxoWTjWxhk8hga9AQU0E4PQJlsuEsZbzsouODjiAc0qrcCAhAV
- DNS ASK pa###bin.com
- DNS ASK i.##gur.com
- DNS ASK oc##.#tartssl.com
- DNS ASK xe##es.com
- '%WINDIR%\syswow64\mstsc.exe'
- '%WINDIR%\syswow64\cmd.exe'
- '<SYSTEM32>\taskeng.exe' {4F012461-A21C-4FB5-8AC5-EE80A5D19BFE} S-1-5-21-1960123792-2022915161-3775307078-1001:bobzpbdhdckj\user:Interactive:[1]