Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'SchMainSTD' = '%APPDATA%\z1618501362\run.vbs'
- %TEMP%\qnisnjpum.exe
- '%TEMP%\qnisnjpum.exe'
- steam.exe
- %TEMP%\qnisnjpum.exe
- %APPDATA%\z1618501362\inst.txt
- %APPDATA%\z1618501362\uninstall\del.bat
- %APPDATA%\z1618501362\run.vbs
- %APPDATA%\z1618501362\ezexit.bat
- nul
- %APPDATA%\microsoft\windows\start menu\programs\startup\steam.exe
- http://fo####put-apa.ro/se.exe
- DNS ASK fo####put-apa.ro
- '%APPDATA%\microsoft\windows\start menu\programs\startup\steam.exe'
- '%WINDIR%\syswow64\cmd.exe' /C ping 1.1.1.1 -n 4 && del %TEMP%\QNISNJPUM.exe
- '%WINDIR%\syswow64\ping.exe' 1.1.1.1 -n 4
- '%WINDIR%\syswow64\cmd.exe' /c %APPDATA%\z1618501362\ezExit.bat
- '%WINDIR%\syswow64\tasklist.exe' /FI "IMAGENAME eq Steam.exe"
- '%WINDIR%\syswow64\find.exe' /I /N "Steam.exe"
- '%WINDIR%\syswow64\ping.exe' 127.0.0.1 -n 2