Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\bitb6bc.tmp
- %WINDIR%\tasks\sihost.job
- <SYSTEM32>\tasks\sihost
- '%TEMP%\2415674.exe'
- %TEMP%\d32.dll
- '<SYSTEM32>\runonce.exe'
- <SYSTEM32>\runonce.exe
- %WINDIR%\syswow64\mstsc.exe
- %WINDIR%\syswow64\cmd.exe
- %WINDIR%\syswow64\cmd.exe
- %TEMP%\d32.dll
- %TEMP%\1040970.dat
- %TEMP%\2415674.exe
- %TEMP%\bitf3a9.tmp
- %TEMP%\1727cef3.png
- %APPDATA%\adobe\logtransport2\logs\bitad07.tmp
- %TEMP%\767dfba8.lnk
- %APPDATA%\adobe\logtransport2\logs\bitad07.tmp
- %APPDATA%\microsoft\windows\start menu\programs\startup\bitb6bc.tmp
- %TEMP%\bitf3a9.tmp
- %APPDATA%\adobe\logtransport2\logs\bitad07.tmp в %APPDATA%\adobe\logtransport2\logs\sihost.exe
- http://oc##.#tartssl.com/sub/class2/code/ca/MEMwQTA%2FMD0wOzAJBgUrDgMCGgUABBQSOgrhRCSnWfKxoWTjWxhk8hga9AQU0E4PQJlsuEsZbzsouODjiAc0qrcCAhAV
- DNS ASK pa###bin.com
- DNS ASK i.##gur.com
- DNS ASK oc##.#tartssl.com
- DNS ASK da####rchllc.host
- '%WINDIR%\syswow64\mstsc.exe'
- '%WINDIR%\syswow64\cmd.exe'