Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\bit104b.tmp
- %WINDIR%\tasks\svp.job
- <SYSTEM32>\tasks\svp
- '%TEMP%\6161690.exe'
- %TEMP%\ibsen.dll
- '<SYSTEM32>\extrac32.exe'
- <SYSTEM32>\extrac32.exe
- %WINDIR%\syswow64\ipconfig.exe
- %WINDIR%\syswow64\cmd.exe
- %TEMP%\ibsen.dll
- %TEMP%\1039002.dat
- %TEMP%\6161690.exe
- %TEMP%\bit6cc5.tmp
- %TEMP%\e58680b7.png
- %APPDATA%\icq-profile\update\bit415.tmp
- %TEMP%\d2c42916.lnk
- %APPDATA%\remcos\logs.dat
- %APPDATA%\icq-profile\update\bit415.tmp
- %APPDATA%\microsoft\windows\start menu\programs\startup\bit104b.tmp
- %TEMP%\bit6cc5.tmp
- %APPDATA%\icq-profile\update\bit415.tmp в %APPDATA%\icq-profile\update\svp.exe
- 're###net.com':2404
- 'pa###bin.com':443
- 'i.##gur.com':443
- DNS ASK pa###bin.com
- DNS ASK i.##gur.com
- DNS ASK re###net.com
- '%WINDIR%\syswow64\ipconfig.exe'
- '%WINDIR%\syswow64\cmd.exe'