Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\update.exe
- %APPDATA%\microsoft\windows\start menu\programs\startup\svhost.exe
- '%TEMP%\client.exe' AC
- '%WINDIR%\syswow64\cmd.exe' /c%tmp%\Client.exe AC
- %TEMP%\client.exe
- %APPDATA%\svhost.exe
- %TEMP%\uuc5dsk2.0.vb
- %TEMP%\uuc5dsk2.cmdline
- %TEMP%\uuc5dsk2.out
- %TEMP%\vbcbc53f6302e0643ea821f3de9964ae1d9.tmp
- %TEMP%\vbcd1a6e6c8427740e2bca794b7f5f57a28.tmp
- %TEMP%\resc5fc.tmp
- %TEMP%\client.exe
- %TEMP%\resc5fc.tmp
- %TEMP%\vbcd1a6e6c8427740e2bca794b7f5f57a28.tmp
- %TEMP%\vbcbc53f6302e0643ea821f3de9964ae1d9.tmp
- %TEMP%\uuc5dsk2.cmdline
- %TEMP%\uuc5dsk2.out
- %TEMP%\uuc5dsk2.0.vb
- 'pa###bin.com':443
- '21#.#70.126.139':3352
- DNS ASK pa###bin.com
- '%APPDATA%\svhost.exe'
- '%WINDIR%\syswow64\cmd.exe' /c%tmp%\Client.exe AC' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\vbc.exe' /noconfig @"%TEMP%\uuc5dsk2.cmdline"' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC5FC.tmp" "%TEMP%\vbcD1A6E6C8427740E2BCA794B7F5F57A28.TMP"' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\vbc.exe' /noconfig @"%TEMP%\uuc5dsk2.cmdline"
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC5FC.tmp" "%TEMP%\vbcD1A6E6C8427740E2BCA794B7F5F57A28.TMP"