Техническая информация
- %WINDIR%\tasks\reg.job
- <SYSTEM32>\tasks\reg
- '%TEMP%\5217887.exe'
- %TEMP%\caress.dll
- '<SYSTEM32>\notepad.exe'
- <SYSTEM32>\notepad.exe
- %WINDIR%\syswow64\ipconfig.exe
- %WINDIR%\syswow64\cmd.exe
- %TEMP%\caress.dll
- %TEMP%\1099887.dat
- %TEMP%\5217887.exe
- %TEMP%\bit9359.tmp
- %TEMP%\bb5eb3e1.png
- %APPDATA%\icq-profile\update\splash_banner\bit2175.tmp
- %APPDATA%\icq-profile\update\splash_banner\bit2175.tmp
- %TEMP%\bit9359.tmp
- %APPDATA%\icq-profile\update\splash_banner\bit2175.tmp в %APPDATA%\icq-profile\update\splash_banner\reg.exe
- http://oc##.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS%2BzcBkvzl4%3D
- DNS ASK pa###bin.com
- DNS ASK i.##gur.com
- DNS ASK mi###ikemic.com
- DNS ASK oc##.thawte.com
- '%WINDIR%\syswow64\ipconfig.exe'
- '%WINDIR%\syswow64\cmd.exe'