Техническая информация
- <SYSTEM32>\tasks\updates\osyohnodrgjg
- '' (загружен из сети Интернет)
- '%APPDATA%\qwertyuiolkjhgfdszxcvbn.exe'
- %WINDIR%\microsoft.net\framework\v2.0.50727\msbuild.exe
- %APPDATA%\qwertyuiolkjhgfdszxcvbn.exe
- %APPDATA%\osyohnodrgjg.exe
- %TEMP%\tmp56fb.tmp
- %TEMP%\9b9c9682-ae0a-8f78-a09c-ba293522862a
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %APPDATA%\osyohnodrgjg.exe
- %TEMP%\tmp56fb.tmp
- http://ro####ade.com.vn/wp-content/images/views/KxAv6dlO4dTXfWq.exe
- http://bo#.####ismyipaddress.com/
- DNS ASK ro####ade.com.vn
- DNS ASK bo#.####ismyipaddress.com
- DNS ASK ma##.##ivateemail.com
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\osYohnoDrGJg" /XML "%TEMP%\tmp56FB.tmp"' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\osYohnoDrGJg" /XML "%TEMP%\tmp56FB.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\msbuild.exe'