Техническая информация
- <SYSTEM32>\tasks\updates\llofwehisrh
- %APPDATA%\llofwehisrh.exe
- %TEMP%\tmp4adc.tmp
- %HOMEPATH%\documents\results.txt
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %TEMP%\tmp4adc.tmp
- http://ch####p.dyndns.org/
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- DNS ASK ch####p.dyndns.org
- DNS ASK sm##.##ivateemail.com
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\llOfwehISrH" /XML "%TEMP%\tmp4ADC.tmp"' (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\llOfwehISrH" /XML "%TEMP%\tmp4ADC.tmp"