Техническая информация
- %WINDIR%\tasks\regsvr.job
- <SYSTEM32>\tasks\regsvr
- '%TEMP%\2178344.exe'
- %TEMP%\keynesianism.dll
- '<SYSTEM32>\extrac32.exe'
- <SYSTEM32>\extrac32.exe
- %WINDIR%\syswow64\ipconfig.exe
- %WINDIR%\syswow64\mstsc.exe
- %WINDIR%\syswow64\mstsc.exe
- %TEMP%\keynesianism.dll
- %TEMP%\1017048.dat
- %TEMP%\2178344.exe
- %TEMP%\bit24d0.tmp
- %TEMP%\1fcc633.png
- %APPDATA%\adobe\flash player\bitbf8a.tmp
- %APPDATA%\adobe\flash player\bitbf8a.tmp
- %TEMP%\bit24d0.tmp
- %APPDATA%\adobe\flash player\bitbf8a.tmp в %APPDATA%\adobe\flash player\regsvr.exe
- 'pa###bin.com':443
- 'i.##gur.com':443
- 'je##d.com':8080
- DNS ASK pa###bin.com
- DNS ASK i.##gur.com
- DNS ASK je##d.com
- '%WINDIR%\syswow64\ipconfig.exe'
- '%WINDIR%\syswow64\mstsc.exe'